# AWS Secrets Manager vs Infisical

**Leader by Vioscale score:** AWS Secrets Manager

| Attribute | AWS Secrets Manager | Infisical |
|---|---|---|
| **Vioscale score** | 77.6 (73% (medium)) | 63.8 (73% (medium)) |
| activity.commits_last_30d | - | 100 |
| adoption.dependent_repos | - | 0 |
| adoption.github_stars | - | 28,974 |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"on_prem":true,"self_hosted":true}` |
| description.long | A cloud-based service that stores and manages sensitive credentials, API keys, and other secrets for applications and services. It provides encryption at rest and in transit, fine-grained access control through IAM policies, automatic secret rotation, multi-region replication, and comprehensive audit logging. | A secrets management solution that provides a single, encrypted repository for storing and controlling access to application credentials, certificates, and privileged access. It enables teams to automatically sync, rotate, and audit secrets across cloud, on-premises, and AI infrastructure while enforcing fine-grained access controls and approval workflows. |
| features.capabilities | `{"hosting":"cloud","tool_type":"store","audit_logging":true,"fips_validated":true,"secret_rotation":true,"fine_grained_policy":true}` | `{"hosting":"both","tool_type":"store","audit_logging":true,"dynamic_secrets":true,"secret_rotation":true,"open_source_core":true,"kubernetes_native":true,"fine_grained_policy":true}` |
| integrations.count | 30 | 6 |
| integrations.list | `[{"name":"Alexa for Business"},{"name":"AWS App2Container"},{"name":"Amazon AppFlow"},{"name":"AWS AppSync"},{"name":"Amazon Athena"},{"name":"AWS CodeBuild"},{"name":"AWS Direct Connect"},{"name":"AWS Directory Service"},{"name":"Amazon DocumentDB"},{"name":"Amazon RDS"},{"name":"Amazon Redshift"},{"name":"Salesforce"},{"name":"Snowflake"},{"name":"AWS Elemental MediaLive"},{"name":"AWS Elemental MediaConnect"},{"name":"AWS Elemental MediaConvert"},{"name":"Amazon CodeGuru Reviewer"},{"name":"AWS Elemental MediaPackage"},{"name":"AWS Elemental MediaTailor"},{"name":"Amazon EMR"},{"name":"Amazon EventBridge"},{"name":"Amazon FSx"},{"name":"AWS Glue DataBrew"},{"name":"AWS Glue Studio"},{"name":"AWS IoT SiteWise"},{"name":"Amazon Kendra"},{"name":"AWS Launch Wizard"},{"name":"Amazon Lookout for Metrics"},{"name":"Amazon Managed Streaming for Apache Kafka"},{"name":"Amazon Managed Workflows for Apache Airflow"}]` | `[{"name":"Checkly"},{"name":"Vercel"},{"name":"AWS"},{"name":"GitHub"},{"name":"Datadog"},{"name":"Anthropic"}]` |
| language.primary | - | TypeScript |
| market.availability | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"usage","plans":[{"free":false,"name":"Pay-as-you-go","summary":"Pay per secret stored per month and per 10,000 API calls","features":["Rotate secrets automatically","Replicate secrets for disaster recovery","Fine-grained IAM access control","Audit and monitor secret usage","Integration with AWS logging and monitoring services"],"contactSales":false}],"summary":"Usage-based pricing. Free tier available for 6 months with $200 credits for new customers. No upfront costs or contracts.","currency":"USD","freeTier":true,"sourceUrl":"https://aws.amazon.com/secrets-manager/","retrievedAt":"2026-08-01T09:07:13.027Z","billingPeriods":["month"]}` | `{"type":"subscription","plans":[{"free":true,"name":"Free","summary":"$0 forever","features":["5 identities","Unlimited projects","100+ integrations","Agent Proxy","Secret Sharing","Secret References and Imports","Secret Overrides","2FA","10 secret syncs","Secret folders","Webhooks"],"components":[{"kind":"fixed","amount":0,"period":"month","currency":"USD"}],"description":"For individuals and personal projects","contactSales":false,"includedLimits":{"projects":"unlimited","identities":"5","environments":"3 per project","integrations":"100+"}},{"free":false,"name":"Pro","summary":"$20/identity/month billed annually (13% savings vs monthly)","features":["Unlimited identities","Unlimited projects","Access Controls","Secret Rotation","SAML SSO","30-day Audit log retention","Secret Versioning","Point-in-time Recovery","25 secret syncs","3 honey tokens","Webhooks","Custom environments","Insights dashboard"],"commitment":"annual","components":[{"kind":"per_unit","unit":"identity","amount":20,"period":"month","currency":"USD"}],"description":"For growing teams looking to boost their security","contactSales":false,"includedLimits":{"identities":"unlimited","environments":"6 per project","honey_tokens":"3","secret_syncs":"25"}},{"free":false,"name":"Advanced","summary":"$40/identity/month billed annually (13% savings vs monthly)","features":["Everything in Pro","Dynamic Secrets","Honey Tokens","SOC 2 Type II","Higher Rate Limits","Custom Roles","SSO & MFA enforcement","90-day Audit log retention","50 secret syncs","10 honey tokens","Gateways","Insights dashboard"],"commitment":"annual","components":[{"kind":"per_unit","unit":"identity","amount":40,"period":"month","currency":"USD"}],"description":"For scaling teams with complex security needs","contactSales":false,"includedLimits":{"identities":"unlimited","environments":"12 per project","honey_tokens":"10","secret_syncs":"50"}},{"free":false,"name":"Enterprise","summary":"Custom pricing","features":["Everything in Advanced","Approval Workflows & Access Requests","LDAP","SCIM","Custom Audit log retention and rate limits","User Groups","99.99% SLA","KMIP","External KMS & HSM Support","Audit Log Streaming (SIEM)","Sub-organizations","Self-hosting or Dedicated Infrastructure"],"commitment":"annual","description":"For large organizations that need SCIM, custom SLAs, and dedicated support","contactSales":true,"includedLimits":{"identities":"unlimited","environments":"unlimited","honey_tokens":"unlimited","secret_syncs":"unlimited","audit_log_retention":"custom"}}],"summary":"From $20/identity/month (annual billing). Free tier available. All paid plans include free trial, no credit card required.","currency":"USD","freeTier":true,"sourceUrl":"https://infisical.com/","retrievedAt":"2026-08-05T13:25:06.726Z","startingPrice":{"amount":20,"period":"month","currency":"USD"},"billingPeriods":["month","year"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | commercial |
| pricing.price_level | low | free |
| pricing.transparent | yes | no |
| release.cadence_days | - | 1 |
| release.history | - | `[{"url":"https://github.com/Infisical/infisical/releases/tag/v0.163.0","date":"2026-08-26T14:07:43Z","type":"stable","version":"v0.163.0"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.24","date":"2026-08-21T19:58:22Z","type":"stable","version":"v0.162.24"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.23","date":"2026-08-21T17:36:59Z","type":"stable","version":"v0.162.23"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.22","date":"2026-08-20T22:43:48Z","type":"stable","version":"v0.162.22"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.21","date":"2026-08-18T12:31:31Z","type":"stable","version":"v0.162.21"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.20","date":"2026-08-17T19:16:39Z","type":"stable","version":"v0.162.20"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.19","date":"2026-08-10T23:18:12Z","type":"stable","version":"v0.162.19"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.18","date":"2026-08-07T18:43:05Z","type":"stable","version":"v0.162.18"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.17","date":"2026-08-07T10:33:40Z","type":"stable","version":"v0.162.17"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.16","date":"2026-08-04T17:48:35Z","type":"stable","version":"v0.162.16"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.15","date":"2026-07-29T21:11:41Z","type":"stable","version":"v0.162.15"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.14","date":"2026-07-27T22:56:37Z","type":"stable","version":"v0.162.14"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.13","date":"2026-07-24T01:16:21Z","type":"stable","version":"v0.162.13"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.12","date":"2026-07-23T02:01:55Z","type":"stable","version":"v0.162.12"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.11","date":"2026-07-21T22:20:09Z","type":"stable","version":"v0.162.11"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.10","date":"2026-07-20T13:15:30Z","type":"stable","version":"v0.162.10"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.9","date":"2026-07-17T23:59:31Z","type":"stable","version":"v0.162.9"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.8","date":"2026-07-17T23:02:36Z","type":"stable","version":"v0.162.8"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.7","date":"2026-07-15T19:38:12Z","type":"stable","version":"v0.162.7"},{"url":"https://github.com/Infisical/infisical/releases/tag/v0.162.6","date":"2026-07-14T01:00:21Z","type":"stable","version":"v0.162.6"}]` |
| reliability.sla_pct | - | 99.99 |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | yes |
| security.fedramp | yes | - |
| security.gdpr | yes | yes |
| security.hipaa | yes | yes |
| security.iso27001 | yes | - |
| security.pci | yes | - |
| security.soc2 | yes | yes |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2FInfisical%2Finfisical%2Fk8-operator&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (Secrets Management Tools)

| Capability | AWS Secrets Manager | Infisical |
|---|:--:|:--:|
| **Core** |  |  |
| Tool type | Secret store / engine | Secret store / engine |
| Dynamic (short-lived) secrets | - | ✓ |
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Lifecycle** |  |  |
| Automatic secret rotation | ✓ | ✓ |
| **Crypto** |  |  |
| Encryption as a service (transit) | - | - |
| **Compliance** |  |  |
| FIPS 140-2/3 validated crypto | ✓ | - |
| HSM support | - | - |
| **Access** |  |  |
| Fine-grained / identity-based policy | ✓ | ✓ |
| **Governance** |  |  |
| Audit logging | ✓ | ✓ |
| **Integration** |  |  |
| Kubernetes native (CRD / CSI / K8s auth) | - | ✓ |
| **Scope** |  |  |
| PKI / certificate authority | - | - |
| **Licensing** |  |  |
| Open-source core | - | ✓ |
| **Ecosystem** |  |  |
| CNCF maturity | - | - |

*Source: Vioscale. Generated 2026-09-01T17:10:56.695Z. "-" = undocumented, not absent.*
