Product
eMCP
vHSM
Garnet
Dyneemes
Buckypaper
Sylica
Nitride
Vault
VAULT · IDENTITIES, SECRETS & ACCESS

One place for identities, secrets and access — every cloud, every environment.

One centralized control point for the database passwords, API keys and credentials modern estates scatter everywhere — with access governed by policy and released only to workloads that have proven themselves through attestation.

On-premise, private, public, hybrid and cross-cloud
Centralized identities, secrets and access control
Attestation-bound release via Nitride
Runs sealed — the store is itself a confidential workload

Centralize the sprawl. Govern by policy. Release only on proof.

One inventory, not five silos

Identity, secrets and access control span every environment you run instead of fragmenting into per-platform rule sets nobody can audit as a whole.

CENTRALIZED · AUDITABLE END TO END
01
Release bound to attestation

A secret is only as safe as the workload it is handed to — so Vault hands secrets only to workloads that have proven their integrity.

STOLEN CREDENTIALS CANNOT IMPERSONATE
02
Sealed by its own medicine

Vault runs as a confidential workload: memory encrypted in use, integrity attested, no readable path for the infrastructure operator.

CENTRALIZATION WITHOUT A BIGGER TARGET
03

Why not a conventional secrets manager?

PER-CLOUD SECRET STORES
ENCLAIVE VAULT
Scope
One store per cloud or platform
One control point across every environment
Access policy
Fragmented per-platform rule sets
Centrally governed, auditable as a whole
Release condition
Possession of a credential
Verified workload identity via attestation
Store protection
Trusts the underlying infrastructure
Runs sealed as a confidential workload
Key custody
Provider KMS silos
vHSM underneath, custody in your hands

Three layers, deliberately separate

Vault
WORKFLOW LAYER

Identities, secrets and access policy across the estate — the layer applications reach for all day.

Nitride
PROOF LAYER

Verifies which workload is asking, so release decisions rest on hardware-rooted identity.

vHSM
CUSTODY LAYER

HSM-grade key protection underneath, where keys need certified hardware roots.

What Vault enforces

01
Secrets, centralized

Database passwords, API keys and service credentials managed in one place — the sprawl becomes an inventory.

02
Identity across estates

Consistent handling for users, devices and workloads on-premise and across every cloud.

03
Access control by policy

Who and what may access which resource is explicit, centrally governed and auditable.

04
Attestation-bound release

Secrets release only against verified workload identity from Nitride.

05
Sealed secrets store

Vault itself runs confidentially — protected by the same operator exclusion it enables.

06
Custody-grade foundations

Connects to the vHSM where keys need HSM-grade custody: workflows above, custody below.

Technical fit
ComponentDetail
Trusted execution
AMD SEV-SNP (EPYC Milan or later); Intel TDX (Xeon Emerald Rapids or later)
Key management
vHSM / Vault integration; attestation-bound key release; BYOK/HYOK patterns
Operations
Managed via eMCP — one control plane across providers; standard image formats
Evidence
Attestation reports and immutable logs, exportable for audit

[PLACEHOLDER — SILICON LIST PENDING THE STANDING INTEL TDX RULING: THE GARNET BRIEF, 5G DOCUMENTATION AND DIANA ONE-PAGER ALL LIST INTEL TDX (AND ARM CCA); THE eMCP PAGE CURRENTLY OMITS IT. ONE DECISION, APPLIED EVERYWHERE.]

Get started

Turn secrets sprawl into one governed inventory.

Bring the estate map — the clouds, the on-prem islands, the credential stores nobody owns.

Certifications & security
Certified ISO/IEC 27001
IT Security made in Germany — TeleTrusT