HashiCorp Cloud Platform managed Vault — fully managed multi-tenant (HCP Vault Secrets) and single-tenant (HCP Vault Dedicated) deployments. Underlying engine is HashiCorp Vault Enterprise. Compliance attestations: SOC 2 Type II and ISO 27001/27017/27018 per HashiCorp's public compliance page. Use this row when you need a managed Vault deployment with vendor-attested compliance; use hashicorp_vault (OSS) for self-host without managed compliance, or openbao for OSI-approved alternative.
HCP Vault is HashiCorp Cloud Platform's managed Vault — Commercial license. Multi-tenant (HCP Vault Secrets) and single-tenant (HCP Vault Dedicated) deployments. Underlying engine is HashiCorp Vault Enterprise. Compliance attestations: SOC 2 Type II + ISO 27001/27017/27018 per HashiCorp's published trust posture.
HCP Vault's managed-service positioning provides BAA + SOC 2 + ISO compliance via HashiCorp. From a Trust Before Intelligence lens, this is the compliance-friendly path for Vault. The audit found that the existing OSS hashicorp_vault row had compliance flags belonging to HCP — those flags now correctly attribute to this row.
P95 sub-100ms secrets retrieval.
Vault HTTP API.
Best-in-class. Token + AppRole + cloud auth + ABAC.
HCP runs on AWS + Azure.
Rich audit logs + telemetry + custom plugins.
Audit log + telemetry.
Best-in-class governance posture.
4/6 -> 4.
5/6 -> 4.
Secrets engine taxonomy.
Mature ACID + replication.
Best suited for
Compliance certifications
SOC 2 Type II + ISO 27001/27017/27018 attested. FedRAMP/HIPAA/PCI/CMMC NOT attested per public compliance page.
Use with caution for
OSS Vault for self-host. HCP Vault for managed compliance.
View analysis →OpenBao for OSI-approved fork. HCP Vault for managed.
View analysis →AWS for AWS-native managed. HCP Vault for multi-cloud HashiCorp ecosystem.
View analysis →Role: L5 managed Vault SaaS.
Upstream: Application secrets requests via Vault API.
Downstream: Audit log + telemetry.
Mitigation: Verify each cert at procurement. SOC 2 + ISO confirmed; FedRAMP/HIPAA/PCI/CMMC require sales verification.
HCP Vault specialty.
Verified attestation.
Use AWS Secrets Manager (FedRAMP via AWS).
This analysis is AI-generated using the INPACT and GOALS frameworks from "Trust Before Intelligence." Scores and assessments are algorithmic and may not reflect the vendor's complete capabilities. Always validate with your own evaluation.