TL;DR: Traditional secrets management still suffers from infrastructure overhead, fragmented control, and weak lifecycle handling, according to Akeyless, while its SaaS model and zero-knowledge design aim to simplify rotation, access, and auditability across hybrid environments. The governance issue is no longer storage alone, but whether secrets, certificates, and machine access can be managed without persistent operational sprawl.
NHIMG editorial — based on content published by Akeyless: modern SaaS secrets management with vaultless and zero-knowledge architecture
By the numbers:
- Only 44% of organisations are currently using a dedicated secrets management system.
Questions worth separating out
Q: How should security teams handle exposed secrets in AI-driven environments?
A: Security teams should treat exposed secrets as active access paths and respond as though misuse can begin immediately.
Q: What do security teams get wrong about workload identity in cloud and CI/CD environments?
A: They often assume short-lived credentials automatically create good governance.
Q: What breaks when secret management is treated as storage only?
A: Storage-only thinking leaves replication, runtime delivery, and offboarding outside governance.
Practitioner guidance
- Inventory every secret-bearing workflow Map CI/CD pipelines, Kubernetes workloads, AI agent integrations, and remote access paths to identify where static credentials still persist.
- Replace standing secrets with task-scoped access Use short-lived credentials for deploy, build, and runtime access wherever workload identity is available.
- Test provider dependence as an identity dependency Validate what happens when the secrets platform is unavailable, delayed, or policy-restricted.
What's in the full article
Akeyless's full post covers the operational detail this analysis intentionally leaves for the source:
- How its vaultless architecture is implemented across hybrid and multi-cloud environments.
- How Distributed Fragments Cryptography supports zero-knowledge custody in practice.
- How the platform handles certificate lifecycle management, secure remote access, and CI/CD injection.
- How its pricing and deployment model are positioned for organisations replacing legacy vault infrastructure.
👉 Read Akeyless's analysis of vaultless secrets management and zero-knowledge control →
Vaultless secrets management: what it changes for IAM teams?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
Vaultless secrets management is best understood as lifecycle governance, not infrastructure outsourcing. Moving from self-managed vaults to SaaS removes one class of operational burden, but it does not remove the need to govern issuance, rotation, revocation, and audit. The control problem shifts from backend administration to identity lifecycle discipline across workloads, CI/CD, and AI systems. Practitioners should treat the platform as an access dependency, not a governance substitute.
A few things that frame the scale:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
- 54% of organisations are dissatisfied with their current secrets management solution because not all secrets are secured, and 43% cite lack of central management.
A question worth separating out:
Q: Who should own zero-knowledge secrets governance in an enterprise?
A: The customer should own policy, lifecycle, and access accountability even when the provider cannot decrypt the material. That means security, IAM, and platform teams must define retrieval conditions, review access regularly, and preserve audit evidence for compliance and incident response.
👉 Read our full editorial: Akeyless and the shift to vaultless secrets governance