TL;DR: Secrets managers still leave a secret zero problem in multicloud environments because every workload must authenticate to the vault before it can receive protected credentials, and static secrets embedded across clouds, SaaS, and CI/CD remain reusable attack paths, according to Aembit. Secretless workload access, not better vault hygiene alone, becomes the governance issue practitioners have to solve.
Editorial analysis by NHI Mgmt Group, based on content published by Aembit: “5 Secrets Manager Alternatives for Securing Non-Human Identities”.
By the numbers:
- Credentials for AI services surged 81% as agentic workflows introduced new categories of machine credentials into production stacks.
- 64% of secrets confirmed as valid in 2022 remained unrevoked heading into 2026.
Key questions
Q: What breaks in practice when applications depend on bootstrap secrets for Vault access?
A: Bootstrap secrets create operational and security failure points at the moment applications first connect.
Q: Why do multicloud environments make secret zero harder to govern?
A: Because each cloud has its own identity model, access syntax, and trust semantics.
Q: How should teams choose between vaults, federation, and workload IAM?
A: Use vaults for storage, federation for cross-environment trust, and workload IAM when access needs to be decided at runtime.
Practitioner guidance
- Map the bootstrap path for every workload Identify how each workload authenticates before it can obtain a secret, then document where that initial trust is anchored and who governs it.
- Reduce shared secrets in cross-cloud flows Replace long-lived credentials used between clouds, SaaS services, and internal platforms with token-based federation or runtime-issued access where possible.
- Separate transport trust from authorization Use service mesh and certificate controls for communication security, but keep workload-to-resource entitlement decisions in a dedicated policy layer.
Bottom line: The core risk is not only where secrets are stored, but how workloads obtain the authority to use them across cloud and SaaS boundaries.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Secret zero is a governance problem, not just a secrets problem. Vaults reduce where credentials sit, but they do not answer how a workload proves it should be allowed to fetch one in the first place. That bootstrap trust dependency is the real control gap, because compromise at the first hop invalidates everything downstream. Practitioners need to think in terms of issuance authority, not only secret storage.
A few things that frame the scale:
- 28.65 million new hardcoded secrets were detected in public GitHub commits in 2025 alone, a 34% year-over-year increase and the largest single-year jump ever recorded, according to the State of Secrets Sprawl 2026.
- 8 of the top 10 fastest-growing types of leaked secrets year-over-year are tied directly to AI services, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: When does a service mesh stop being enough for workload access control?
A: A mesh is not enough when the question is whether a workload should reach a specific resource under a specific condition. It can secure the channel, but it cannot make the entitlement decision that workload IAM or a similar policy layer is designed to make.
👉 Read our full editorial: Workload IAM closes the secret zero gap in multicloud access