Join our Newsletter — 33% off our NHI Course
Home FAQ Architecture & Implementation What is the difference between a cloud password…
Architecture & Implementation

What is the difference between a cloud password manager and a self-hosted password vault?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Architecture & Implementation

A cloud password manager runs on the vendor’s infrastructure, so the vendor patches, hosts, and operates the service. A self-hosted vault runs on infrastructure the organisation owns or directly controls. That means the organisation gains custody and policy control, but also takes on patching, backups, uptime, and access management for the server itself.

Why This Matters for Security Teams

The choice between a cloud password manager and a self-hosted password vault is really a choice between delegated operational trust and direct control. For security teams, that distinction affects patch velocity, audit scope, incident response, and who is accountable when a secret is exposed. A cloud service can reduce local operational burden, but it also expands third-party dependency and concentrates risk in the vendor’s control plane.

That matters because secret compromise rarely stays inside the password tool. Once a vault is breached, attackers typically pivot to sessions, APIs, and privileged workflows. NHIMG research on the Guide to the Secret Sprawl Challenge and the 2025 State of NHIs and Secrets in Cybersecurity shows how often secrets are duplicated, exposed, and overused across systems, which makes the vault decision part of a broader governance problem rather than a tooling preference. Current guidance also aligns with NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls, which both emphasize governance, access control, and resilience over convenience alone.

In practice, many security teams discover the real cost of the model only after a vault outage, a misconfigured share, or a leaked admin token has already widened the blast radius.

How It Works in Practice

A cloud password manager is operated by the provider, so the organisation consumes a managed service and inherits the vendor’s patching, scaling, encryption implementation, and availability model. A self-hosted password vault is deployed into the organisation’s own environment, which gives the security team more control over data residency, network paths, and administrative boundaries, but also makes the organisation responsible for the server, the database, the backups, and the hardening of every supporting component.

The practical differences show up in four areas:

  • Operations: cloud services usually simplify maintenance; self-hosted vaults require upgrade windows, monitoring, and recovery testing.

  • Access control: cloud tools often integrate quickly with SSO and device policy; self-hosted tools may need more hands-on integration work.

  • Incident response: a cloud incident requires vendor coordination; a self-hosted incident requires internal containment and full-stack troubleshooting.

  • Auditability: self-hosted deployments can provide tighter evidence collection, but only if logs, admin actions, and backup integrity are actually retained and reviewed.

For many teams, the key question is not whether the vault is hosted in the cloud, but whether the organisation can prove who can access it, how secrets are rotated, and how quickly a compromised credential can be revoked. NHIMG’s NHI Lifecycle Management Guide is useful here because vault choice only becomes meaningful when tied to lifecycle controls for issuance, storage, use, rotation, and retirement. A self-hosted vault can reduce dependency on a third party, but only if it is managed with the same discipline as any other tier-one security service.

These controls tend to break down when the vault is treated as a one-time deployment instead of a continuously maintained system, especially in organisations without dedicated platform ownership.

Common Variations and Edge Cases

Tighter control often increases operational overhead, requiring organisations to balance sovereignty and customisation against staffing, uptime, and recovery risk. That tradeoff is especially visible in regulated environments, air-gapped networks, and teams that manage both human and machine credentials.

There is no universal standard for this yet, but current guidance suggests the right model depends on the blast radius of compromise and the maturity of the operating team. A cloud password manager may be a better fit when rapid rollout, strong vendor SLAs, and low internal admin overhead matter most. A self-hosted vault may be preferable when the organisation needs strict data locality, custom network controls, or direct custody for high-value secrets.

Edge cases matter. For example, a self-hosted vault can still be a poor security choice if patching is delayed or backup recovery is untested. A cloud password manager can still be a strong choice if the vendor offers robust logging, strong identity integration, and clear administrative separation. In both cases, the real risk is secret sprawl, not just storage location. NHIMG research in the Top 10 NHI Issues and the 2025 State of NHIs and Secrets in Cybersecurity shows that duplicated and overused secrets can undermine either model if lifecycle discipline is weak.

In practice, the better answer is often not “cloud or self-hosted,” but “which model can the organisation operate securely every day without losing control of secrets lifecycle and recovery.”

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Vault choice affects where NHI secrets live and who controls them.
NIST CSF 2.0PR.AC-1Identity and access governance is central to vault administration.
NIST SP 800-53 Rev 5AC-6Least privilege limits damage if the vault or admin account is compromised.
NIST Zero Trust (SP 800-207)SC-7Zero trust helps reduce trust in the vault host, network, and admin plane.
NIST AI RMFAI risk principles help when vaults protect machine and agent credentials.

Classify vault-stored secrets as NHI assets and enforce custody, rotation, and recovery controls.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org