Think we're good to get started. Welcome, everybody. And today, we are going to talk about Akeyless versus HashiCorp Vault. We have also a live demo for you. And we're gonna talk about architecture mainly and how architecture matters in this conversation. As we get started, please, go ahead and type your questions in the q and a, and we'll have some time for q and a at the very end. Alright. I see a couple of folks have their hands up. If you do have questions, yeah, please put those in the q and a, and, we'll be sure to to get them get to them. So welcome. My name is Sam Gabriel Gabriel. I'm a platform engineer with, TechEnate Solutions, and I have, worked in the DevOps space for some time. I actually started my career as a network engineer, spent some time there in the telecom world, and then moved into DevOps, worked for companies such as Docker, Sysdig, and HashiCorp. And recently, in the last three years or so, I have been creating content, building a YouTube channel, building blog posts, videos, and also online courses and doing training. And, joined with me is doctor Connor Mancone. And if you wanna introduce yourself, Connor, that would be great. Hello, everybody. Yeah. My name is Conor Mancone. My background, my training is actually as a research scientist, but I left the the ivory tower for the corporate world with everybody else. And, I spent maybe fifteen, twenty years as a software engineer. Although security was always, like, kind of, like, I guess, my passion, really. And so I then transitioned to become a security engineer a security architect, which is where I spent my last, five or so years, before joining Akeyless. And so as a security architect, there was a couple services I managed, at the at my past company, but, you know, one of the primary ones was secret and management. And so I managed HashiCorp Vault, and I also, you know, helped see us through a migration onto Akeyless. So so I'm very familiar with both sides of the aisle. So that's that's me. Perfect. Thanks, Connor. Okay. So a few slides, and then we'll jump into a demo. And the agenda for today's webinar, we're gonna talk about why secrets man management matters in the first place, some of the challenges that we find with Vault, and how Akeyless solves these challenges, deep dive into the architectural differences. And if you forget everything we say today, I really want you to to focus on the architecture and how that really matters, when it comes to cost, when it comes to building complexity and everything else. Then we're gonna have a demo walk through. So first off, why secrets management matters. Keeps passwords, keys, and credentials safe. So if you're not familiar with secrets, secrets could be anything, can anything that you deem sensitive in your organization. So passwords, like, API keys, certificates, credentials. And it is it's really essential for companies to protect this data and their systems, helps avoid breaches and costly downtime. Now the challenge that we we see with Hashgraph Vault, first off is high licensing fees and hardware costs, and a complexity when it comes to setting it up and managing it. I've built a number of Vault clusters over the years for my customers, and, we always have a track for operations and track for actually DevOps and the teams that are actually gonna use Vault. And in the operations track, we talk about how to deploy the clusters, how to manage it, how to scale, replicate, and all that good stuff. We'll see that on a separate slide talking about architecture. But because of that, that's why there's high licensing fees and also hardware costs associated with it. Requires clusters in every geographic region. So if you wanna scale your secrets management platform, and typically, you wanna have a cluster in every region where your applications live, and then it requires that you manage those clusters and scale them and take care of them and so on. Not all secrets are replicated. There are two main replication mechanisms in HashiCorp Vault. There is disaster recovery and there is, performance replication. So if you're running with performance replication across geographic regions, you have to be careful what gets replicated. So static secrets get replicated, but anything that is dynamic with a time to live, so dynamic secrets, tokens, and so on, those do not get replicated. There's a reason for that. Hashicorp is pushing for short lived credentials, which we all agree that that should be the norm. But when you're designing, you have to be careful to know what your application does. Is it an active active mode, active standby? So a lot of consideration has to be put in place when you're designing. Plus a steep learning curve is needed for for teams if you're gonna really use Hashgraph Vault at us at scale. Which brings us brings us to Akeyless. Akeyless is a cloud native true SaaS secrets management solution, easy deployment and zero maintenance as you'd expect from a SaaS solution, and it has a pay as you go pricing model. You might be thinking your head, well, Sam, what about HCP Vault? They offer also a SaaS solution. Hashcorp has been moving towards SaaS solutions for all their products for some time now. We will get to that. And if I forget, please keep me honest, you can ask the question again in the QA. Our focus right now is with Vault self hosted, where you are taking care of Vault yourself. You're hosting it either on prem, and or in a public cloud or VPCs that you own. So quick comparison when it comes to the architecture between Hashgraph Vault and Akeyless. You'll see on the left hand side, we've got Vault. It requires a full cluster in every region, whereas Akeyless uses something called gateways and these are stateless, lightweight. They could be containers in Docker Docker containers or they could be, running in Kubernetes. We'll see an example in the demo. And they run-in the edge of your private network. On the Hashgraph side, high hardware cost and licensing fees per cluster. Whereas with Akeyless, the gateways connect to the SaaS back end outbound, and so you don't have to open any files inbound and so on. So there's really no hardware cost associated with that. Very minimal, I should say. And then on the vault side, complex to manage across regions, whereas with Akeyless, it's much easier to set up and far less costly. Which takes us to the HashiCorp Vault architecture. When we talk about a Vault cluster, the recommendation, the reference architecture from HashiCorp, if you're running Vault with Raft back end storage, or another, documentation, you might, hear it called integrated storage. If you're doing that, then the recommendation is to have five nodes or five servers in a cluster. So one is gonna be active, the rest are gonna be in standby. And the idea is that you can lose two nodes and still be running the cluster. So if you're taking one out for maintenance and you happen to have a failure, then you're you're still okay. You're integrated state, but you're still okay. So just remember, there are five servers involved in every vault cluster. So you may have an active vault cluster in a central region, one maybe on the West Coast. Actually, in this diagram, I have, one in the West, one in the East, and they say active from a performance replication perspective. So you're gonna have a a primary for performance replication where it is the system of record for writing data into the database of vault. And then you have performance replication that are active in West and East Coast. So they're all active. They're all running in active active mode. And then you're gonna have standby clusters that are used for disaster recovery replication. And depending on your architecture, some folks will run those clusters in region, some will have them out of region. In this diagram here, I have them in region. So the West Coast uses disaster recovery in the West Coast and central and central, east and east, but you can have West disaster recovery application pointing to central, central to east, and east to west. That's also a possibility, but it all comes back to the application and how your application run. They could be running in an active active mode. They could be running in an active standby node. So it really depends, and I've had customers say that, you know what? Our applications can never cross regions. So whatever happens in the central region cannot be moved over to any other regions. In that case, you have to do your, disaster recovery in region. So with that, though, you have to pay attention to what gets replicated as well as I mentioned in an earlier slide. For performance replication, no leases get replicated. No tokens get replicated. No dynamic secrets get replicated. The idea is that your west region will serve or your west region cluster will serve the applications that live in the West Region and Central for those applications in Central and East for those application in East and so on. So if this whole cluster or the whole region fails, then you have to figure out a way to see how your applications either flip over to the central region or, depending on whether the cluster failed or the whole region failed, you have to have some logic in the application to reauthenticate into a cluster in another region and recreate the dynamic secrets or tokens that are needed in that region. So that's where the complexity comes into play. You have to be aware of what needs to happen. You have to let your application developers really know how Vault works because it really depends on what they're doing and how they're gonna utilize it. Whereas with disaster recovery, they're these clusters are in standby, so you can't really talk to them. You can't, do anything with them. They're they're just replicating data continuously, and everything gets replicated to disaster recovery. So all the static dynamic tokens, everything gets replicated. In case of a disaster, you can promote one of those clusters to become primary, and then you can, recover from that. So just just very, very high level of what to expect when you're architecting for Vault. Akeyless. Akeyless is, like I said, a back end SaaS offering. So they have gateways that you would install in the different regions, and those gateways will talk to the back end. And, basically, the gateways, you will talk to the gateway in that region, and all the secrets are locked in that region. But, of course, they can replicate over to to the back end. So when I first talked to Akeyless, my biggest concern being a SaaS is like, well, okay. It's a SaaS, but from a security point of view, doesn't Achilles get access to my secrets? I'm sure they have the security measures in play, but at the same time, how can I trust a SaaS offering with with my secrets? Right? So I had some doubts there and concerns, and then, someone from Akiva has told me about their technology called distributed fragment distributed fragments cryptography or DFC for short. And what this allows you to do is basically, you'll have your keys. Your encryption keys are actually broken up into different fragments, fragments in Azure, one in GCP, one in AWS. And you as a customer will have one of those fragments that exist in your own, location, your own gateway that we were just talking about. So Akiles DFC enables Akiles to perform cryptographic operations without ever combining, the encryption key. And like I said, one of those key fragments will be in your own environment where Akiles itself has no access. So as a service provider, Akeyless won't be able to decrypt any of the data that you're storing, and this is what they we call zero knowledge architecture. Of course, it's, FIPS one forty two dash two certified, and this is a patented technology. And if there's more questions around that, please save that for the q and a as well. One other benefit, I was talking to Connor earlier, and he mentioned that not only that, but for admins as well, they don't have access to Akila's secrets if they're if we're using DFC keys. So if someone created, secrets with DFC, an admin will not be able to view those. So it really implements least privilege principles, which is not as straightforward when you're using Vault with something like the root token and and even admin policies. It's not as easy to do. Anything you wanna add here at all, Connor? No. No. I think that's a great summary. And, yeah, you know, just to clarify on that last point because it's, I think, a very helpful use case in many in for many people depending on your security posture, because there have been cases where businesses have had their secret manager breached. And as you can imagine, that goes badly. And so, you know, with that DFC, you know, your your sub tenants and your sub admins who might also be helping you manage both for, like, a department or a team or whatever. Yeah. They can they can deploy their own gateway that only they have access to. And as a result, the Achilles admins won't have access to the secrets, but they'll still have visibility because it's still hosted in the same SaaS. So you get that centralized governance you need without creating centralized risk, which is just a nice a nice thing to be able to do, I find. Yeah. Yeah. Absolutely. Yeah. And with that, actually, we have a case study, Semprest, and, pass it back to Connor to talk to us about it because it's near and dear to his heart. Yeah. Yeah. I guess I did mention. Yeah. So I I originally, I've worked with both Vault and Akeyless. And when I joined Simpress as a security engineer, originally, I got I was put in charge of our Vault cluster at the time, and it needed a little bit of TLC. The person who had, created it had left the company before me. And our Doctor was broken, and, actually, the the Terraform that they had used to deploy the whole thing, they hadn't pushed up their past few commits. That's always exciting. Right? You know, that sort of challenge. And so, you know, I had to revive it and then help the team figure out how to use it and manage it. And it was, you know, it it had its challenges. Right? Upgrades was kind of one. You know, the upgrade process was kind of painful, and it was not not really enjoyable for us. And we at least in those early days, we often discovered bugs while we were practicing our upgrade and would have to go back and forth with Hapch support. And, you know, there were some important features missing for us. You know, we were very serious about secret rotation, and there wasn't any automatic secret rotation functionality involved at the time. I think they've added a little bit since, but Akeyless has that rotation secret rotation as, like, a, a, you know, primary feature set throughout the whole platform. And so we had some challenges with it. And so when we're coming up on contract renewal, we decided to, like, hey. What are our different options out there? And we did run into a keyless, and tested it out. And, really, it just took a couple weeks to realize, you know, this was a real I mean, it sounds like, sounds a little bit, too much maybe, but the reality was it was exactly what we needed. It came with those automatic feature rotation capabilities. The SAS, because this you know, we do have the gateways we deployed locally to bring in some key feature sets. But since everything was backed by the SaaS, disaster recovery is just was no longer a thing. And so we found it to be a great solution for us, which is, you know, really helpful because, you know, as we see right here, we were a small team. You know, the security team itself was maybe thirty people total in a company of twelve thousand. So it's not like we were managing people's, secret management needs ourselves. You know, we needed to be able to delegate to other team leads, and we need to have a just a really clean and easy way to help them do what they need to do while also managing the infrastructure ourselves. And so, Akeyless really just fit in that perfectly. And so, we made the switch. And, you know, the next slide. And overall that that worked out really well for us so one of the questions I'll touch on it in the Q and A is about a licensing comparison and I'm afraid I don't have one, not an exact one because naturally, HashiCorp Vault protects their pricing very carefully, you know, if you're looking to implement, HashiCorp Vault Enterprise, you pretty much have to go through a POC with them and get an official quote. They don't publish that pricing on their website. But overall, I think I have seen pretty consistently, again, I'm, you know, just roughly because I don't have exact numbers, that the licensing fees for Akeyless are typically at least fifty percent lower, than they are for HashiCorp Vault. So usually, you'll get a good discount right off the top. And then, of course, we saved more money because the infrastructure cost decreased dramatically. I think, we probably saved, like, another seventy five to eighty percent off of our infrastructure costs, and the ongoing maintenance were substantially less. We actually ended up fully automating the upgrade process for our gateways with the keyless as opposed to having, like, a full manual, like, testing process with, HashiCorp Vault. And so we'd saved saved a bunch on licensing fees, infrastructure cost, and man hours, you know, managing it. So it was it was a great win for us overall. And, generally, you know, the peep people liked it. It was not actually a required service for our engineering teams to use. You know, we just wanted to make sure that people had a good secret management solution available. And over the net course, in the next couple years, we had, adoption of Akeyless just continuously grow, compared to what it was in HatcherCorp Vault because it was if these people liked it. So that's pretty much, I think, the the main summary of, what that process was like for us. Amazing. Thanks, Connor. Yeah. So, we can we can look at cost comparison from this perspective, from a cost factor where, just like Connor was saying, from an infrastructure per perspective, you you need multiple clusters per region. And as you grow and scale out, costs will grow with you, of course, because you're gonna need more more cluster, more infrastructure, more hardware, whereas it's lightweight for Akeyless with only their gateways that they have to to use within their private, networks. Licensing is a per cluster licensing plus the usage. And for Akeyless, it's a subscription model. Operations, I would say, one dedicated full time employee for for Vault. Again, it really depends on how big your your environment is and, how many clusters you're running and so on, and probably a quarter of that for, Akeyless. Some hidden costs, so hardware refresh, Doctor, some downtime. For a keyless, it's it's mostly all included. And, yeah. So forty to seventy percent total cost of ownership production. It grows as your environment, as you can imagine, grows as well. Right? So the the savings will be a lot more. Okay. So we're we're gonna jump into a demo. And, what I wanna walk us through is, kind of like the dashboard to see what it looks like. One of the really cool things I liked about Akeyless when I started looking into it was their UI. It's really nicely polished and, you can pretty much do a whole lot, like, not everything through the UI. If you're familiar with Vault, the UI has always been playing catch up with their API and CLI. So I'd like to like I suggest to show you what, what's there, and then we'll talk about static secrets. That's typically what I see what we see in, customer adoption of a secrets management solution. We usually start with static secrets. Let's centralize all our secrets that are everywhere in spreadsheets, in, in the code, in in under somebody's keyboard on a sticky note. Let's move those all into a centralized centralized location, and usually people start with static secrets. And then gateway in action, we're going to show the architecture since, again, everything we're talking about really depends on the architecture. So I wanna show us where the gateway lies and, how I have it running in my home lab as a Kubernetes, deployment as a Helm chart, deployment. And then we are going to talk about, automatic secrets rotation. I think Connor alluded to that. And we'll see dynamic secrets. We'll see how to generate temporary secrets for AWS. So this is a feature that Vault has had for a long time and also Keyless has that covered as well. And also multi vault governance with something called universal secrets connector, which allows you to have control over secrets that are in other places as well. So you may have secrets that live in AWS Secret Manager, GCP Secret Manager, or Azure Key Vault, or even HashiCorp Vault itself. And sometimes you're you have to do that, but maybe you're working with other teams and they they've standardized on it or it's hard for them to migrate yet. So you have that option to be able to manage all of that from within a keyless, and we'll see a two way sync that works for, AWS secret manager. We, kinda chose that as our example. So let's jump into it, and let me pull up my screen here. Okay. So what you see here, I've got two screens. I've got the the gateway. I'm logged into the gateway on my local, network here. You see one ninety two and sixty one dot eighty two and port one and eight eight eight eight. And this is the actual SaaS back end, and you can see the difference here. It says gateway underneath. And then I've got my AWS secret manager here. We'll we'll, we'll see that at the end of the demo. Alright. So I also changed the kind of the the background here. This is a light theme for, for the, console or the back end SaaS and then dark theme for the gateway to kind of, contrast the two. So let's start off with items. So when you get into the UI, the first thing you're gonna see is items, and items really is all your secrets. Right? So if you look at new here, you can see encryption. So you can you can create encryption keys with DFC or classic encryption that you can use for encryption encryption as a service if you want later. Here's the static secrets. So you can create any static secret in any location. So similar to Vault, a keyless has is based on paths as well. So you can create those in certain paths, certain folders. So if I use this universal secrets connector just so because I have it here, let's say, my static secret, give it a description, a tag, delete protection, type is generic, could be password. Protection key, you can have different protection keys that, you've created. We'll just leave it as default. Key value pair, I can say whatever, foo bar something, and we can click finish. And there we go. We have our static secret inside of this folder, and you can see the value down here. I can open it up. You can see the value, and you can see also the different versions. So you can have different versions of the same secret. What else? We got, rotated secrets. You can also create rotated secrets that we'll see in just a second for AWS where we're gonna rotate the connection between a keyless and AWS automatically or on demand. We also have, dynamic secrets. There are multiple dynamic secrets that we can build for different databases, cloud, Kubernetes, RDP, some infra. You can see GitHub, for example, Docker Hub, Ping, RabbitMQ, Venify, SSH cert issuer, PKI cert issuer, tokenizer, certificates, USC, which is universal, secrets connector. Like I mentioned before, you can, do this for AWS, Azure, GCP, Kubernetes, and HashCorp Vault. So Akiles becomes the control, the controller for all of these secrets managers and also an OIDC app as well. Okay. So we saw secrets. The next piece is authentication. So if you've seen any of my videos in the past, I'm I'm big on, secret zero. And what secret zero is is basically how do you get to the first secret? And the first secret is to authenticate into your secret manager, that's secret zero. Once you're in, then you can retrieve all your secrets. It's a bootstrap problem, basically. How do you get to that? So with authentication, there are many ways to authenticate. And I always say when you're authenticating into a secret manager, just think of are you authenticating a user, a human, or are you authenticating a machine? So some of these are, humans like, email, LDAP, YDC, SAML. Some are for machines, and some can be used for both. So you can use API keys, universal identity, one of my favorite for on prem. So if you're running applications on prem and you wanna be able to authenticate into a keyless, this comes in really handy because on prem, for the most part, will not your VMware will not create a resource with a fingerprint and ID that can tie it back into, Akeyless. Whereas, if you're running with a cloud, like if you're running an EC two instance, an Azure VM or GCP VM or an OCI VM, those platforms provide an identity to the resources that they spin up. So that way, you can actually use one of these authentication methods to elegantly solve the secret zero problem, and and go from there. Alright. So that's authentication. Once you've authenticated into Akeyless, there is the authorization mechanism after that. And authorization in Hashgraph Vault uses policies. Policies are probably one of the most it can get really complicated and it can trip up a lot of folks because you need to really understand the vault API to understand the path that you need, and what capabilities you need to put on that path. So with Akeyless, you can create access roles and those access roles will be tied to your authentication method methods and a set of rules. So let's grab an example here. This demos one, for example, you can see where it's located. Once again, it could be anywhere in a path. And then you can see the different auth methods that we've got here. So I have an auth method that's a JWT token that can use with, GitHub pipelines. So that way you can authenticate nicely into a keyless. Here's an API key and the Kubernetes auth method. So for all these three auth methods, we have rules and those rules allow you to, read, list, update, delete, and create for anything that is stored, any secrets that are stored under the demos, recursively under the demos path recursively. And you can see the type here is items. You can also create for other types like access rules for access rules, off methods, targets, secure remote access as well. You can also have admin rules also, so you can see things like audit logs, analytics, gateways, and a whole lot more. So we talked about secrets. We talked about the authentication mechanism into Akeyless, and we talked about the authorization mechanism. Targets is really neat because you can create targets that are tied directly into the the the third party system you wanna, create dynamic secrets for, for example, or rotated secrets for. So targets come in handy from a configuration perspective. Then gateways, this is where the architecture matters. Like I said before, I have a gateway running on my bare metal k three s Kubernetes cluster. You can see the gateway URL right here. You can manage the gateway. Zero knowledge encryption is where you can put your customer fragment in here and a whole lot more that you can do for managing that gateway. If you're interested in seeing that in my terminal, I've got two instances of the gateway running here, two pods that are running. And I have a load balancer, and you can see the one eight eight eight eight is the one that's exposed the port that is exposed that we're able to, see the UI on. What else did we say? Okay. We wanna see the the dynamic secrets real quick. So if we go into items, you can view items by folder. You can switch that to see the items directly like this. So if I jump into my AWS Lab Zero demos okay. This is a dynamic secret. I can quickly click on get dynamic secret. I get my username, access key ID, and secret access key expires in an hour. So So I can get this from the UI. I can get this programmatically from the API or from the CLI. So this is what we're trying to get, you know, the community to adapt in terms of short lived credentials. We don't want everything to be static secrets. We wanna move to dynamic secrets. And the reason for that is that your applications actually are very bad at keeping secrets. By accident, somebody, who's know, a software developer might be, might have left a debug on that can spit out some of those secrets, in production that get moved into a monitoring system, and, and we end up having problems. But if it's a dynamic secret, then it won't really matter after an hour that gets rotated automatically. I shouldn't say auto rotated. I should say that the application would request a new dynamic secret and, and and that's that. And oops. I got kicked out. Let me get back in here. Anything you wanna add, Connor, while I log back in? No. I think that's a great summary. You know? And, actually, there is a related question in the q and a about, you know, what options are available for managing past database services and, you know, platform as a service, database services in the clouds. And and so it's really that and it works exactly that same way. You know, each of those databases we support and and the list of targets, you know, those would be how you connect a keyless to your your, platform as a service database, whether that's MySQL or Mongo or whatever database. Actually, just real quick, if you don't mind, Sam, can you go to targets and hit new? So you can see, like, at the very top is all the list of the databases that have built in support for Akeyless. And so you can connect that to those databases whether they're self hosted or hosted in one of the major cloud providers. And from there, Akeyless can set up rotators and dynamic secrets. So problem solved. Yep. Yep. Yeah. And to that end, I mean, if you go back to items and this is what, Connor was referring to earlier for rotated. So remember when we're creating dynamic secrets with that target that Connor just mentioned, we want to we need the keyless to be tied into AWS. And to tie it into AWS, we need credentials. But guess what? Those credentials are gonna be long lived. So we need some sort of a way to rotate those credentials, and we have that here with as a rotated secret. You can see that we have by default, it's thirty days. I just rotated it yesterday. But you can go ahead and rotate that. You can see the value. We can go ahead and rotate that on demand as well. But, again, you set it and you leave it, this will automatically get rotated every thirty days. Okay. Last I wanna show is the universal secrets connector. Okay. This successfully rotated our secret. Good. So if we go back to our items, and I have it in this folder here, and USC AWS. So I've set this up where I can view all the secrets that are in my AWS account right now. So you can see is right here. I can create a new one. So call it, my super secret or something. Give it a value. I don't know. Hello. Save that. Alright. So if we go back so we created it from a keyless. If we go in here and refresh it, it shows up in AWS, and you can do the opposite as well. So if you do a key pair, call it, from AWS secrets. Let's call it that. Next. Secret name. Something like that. And then go next. Next. Store. And refresh. K. From AWS secrets. If you go back here and refresh, this should show up. And there we go. So we have a two way sync between your your other third party secret manager and Akeyless. And, again, those works with Azure, Hashgraph, Vault, Kubernetes, and GCP as well. Okay. That's it for the demo. We do we have Yeah. We got some questions waiting for us. Yeah. So what do we got here? What about open source Vault? Oh, yeah. Okay. Great question. So which actually reminds me of HTTP Vault as well. So I'll I'll I'll talk about both. So, open source Vault is, it it's community edition. We don't call it open source anymore because it's not, truly open source. If you're to take the the the bits and try to compete with Vault, that's in violation of their license. If you were to use it in your environment just as a secret manager without competing with Hashgraph Vault, then you're you're fine. But you still you still need to worry about, what you're gonna do with replication. So it's it's fine to use it in one region. Right? You can you can take snapshots. Snapshots are one point in time, but there's no active replication that happens. So you can't have that disaster recovery. You would have to pay HashiCorp for their enterprise license, and you can't replicate across region as well. So either you build something, yourself to be able to to do that, or you'd have to go to their enterprise, solution. So, yeah, the open source will do its job to a certain degree, but once you start to and I've seen this quite a lot even when I used to work at HashiCorp is that folks usually start small with with enterprise, but then they'll hit a a point where multiple teams now wanna, store their secrets in, in in the secret manager, and then they're gonna run into issues as they scale into multiple other regions. Hcp Vault really, really quick. Yeah. It's it's it's a SaaS, but you have to be careful because it's the same architecture as their enterprise. All they're doing is that they're hosting it for you. So they still need the same architecture. They still need the to have their clusters in multiple regions, and they'll charge you per replication, and they'll charge you per so per, performance replication costs more than disaster recovery, and, and they'll charge you a premium for hosting it for you. So it'll be more expensive than if you were to use your own hardware. On top of that, the HCP Vault doesn't have this DFC technology, which makes some people a little bit hesitant because then, you know, what what can prevent somebody from seeing the admin tokens inside of HCP Vault. I'm sure they have very good security measures in play, but at the same time, this is something that goes in the back, mind of many, customers as well. Okay. Do we have any other ones? It's I I would also add in real quick there, that, you know, that on the, the SaaS version of patchwork vault, you know, one of the challenges one of the other challenges we had in Sempress was that that kind of idea that, hey. This is your vault that need to connect your applications. But but we were in this kind of zero trust world where we had extreme network fragmentation intentionally, you know, as a security thing. We we moved away from having one giant corporate network to hundreds of AWS accounts sometimes with multiple VPCs in them. And so if you wanted to use a centralized secrets management service like Vault, I mean, you just couldn't. There was no way to connect our Vault cluster to all of those different networks, which meant that we couldn't use the Vault cluster with our different databases and other network left resources. And and so, you know, we had this huge feature set of Vault that we just couldn't use. And and, again, that problem still continues in with the SaaS because if you set up the HashCorp Vault SaaS, kind of one of the questions they first questions they ask you is, what cloud provider are you in, so that we can set up network peering to your networks? And, again, that that's fine if you've got one or two or three networks, but it quickly becomes a scaling problem. Nice. Yeah. No. Thanks for that. I see Sandeep is asking about, after auto rotation of secrets, does it require application restart or exception handling, or what's the best way? Thank you. Yeah. So great question. The so whether you're using auto rotation or dynamic secrets, the the application itself, depending on how it's it's it's written, it has to have some logic, some kind of a retry logic, to be able to see, hey. If I fail to access my third party, maybe database, to do a retry to to to get it again because the connection pool needs to re get restarted for the new application to get in the new, secret. So that's typically how you'd architect it, but that goes for anything, whether it's Hashtag or Vault, whether it's it's Akeyless. The application needs a way to know that, hey. I failed. I'm gonna do a retry to be able to get the new, credentials. Although there there are some exceptions, when you're talking about specifically rotation. It depends on the database I've found because a lot of the databases so I've tested this extensively with, like, my SQL just because that's one I've used in the past. And a password change does not disconnect open sessions. And so if all you're doing is rotation, that actually can be an easy one to adopt for teams that are trying to move away from fully static secrets. Because in those kinds of databases, your application can simply start up, fetch the current value of the rotated secret, connect to the database, and move on with its life. And if that password gets rotated while it's still connected to the database, it it it won't interrupt it at all. There's no session disconnect. It's not forcibly disconnected, so we can just continue using that connection until it's, you know, eventually, it's cleaned up and, right, and then the next one does the same thing. And so it does depend a little bit on your databases. Some make this easy. Some of them, like you're saying, you know, they'll get forcibly disconnected and then they have to know to reconnect. We we do also have some help from, with Kubernetes, people running Kubernetes. We have our, secrets injector, and so, that actually has kind of a native integration and knowledge of what's going on in the keyless. So if there's a rotation event, it will actually automatically relaunch the affected pods and, you know, reprovision new secrets to them. So you don't necessarily have to build in the logic of, you know, checking for new credentials into your application itself. So, generally, you know, you often do have to make your applications be aware of that, but sometimes there's ways where you can avoid that whole problem and make your life easier. Great. I see another one here. What options are available for managing past database services in clouds, AWS, GCP, Azure? Any thoughts on that one, Connor? I'm I'm guessing maybe like an RDS. Yeah. And I and I think that's where, it's just a matter of from from the Akita's perspective, you know, whether it's it's, on prem self hosted database or one that's being managed directly by the cloud provider like RDS. Achilles doesn't really care. Like, they still operate like regular databases, so you can still connect to them using Achilles. You just provide it with the passwords, create your target, and set up automatic rotation and whatnot. We have a lot a lot more coming in. So so real quick, so you no. Go ahead. It looks like you're on top of that next one, Sam. Yeah. I mean, this is one of my favorites. I think, who was it? The the the was asking, does Akiva's provide a solution similar to HashiCorp Vault plus Boundary for session recording. Right? So, it's called secure remote access, basically. Right? And this is one of my favorite because it's bundled into the solution rather than, having to stitch both and boundary together. I mean, HashCorp has done a better job over the over the course of time to bring those two solutions closer to each other, but you have to remember there are two different teams that were working on it. But it's right out of the box here with Akeyless. I think it's just a a license an additional license. You can correct me if I'm wrong there, Connor, but it it works very well. Unfortunately, I don't have, it set up here in my demo. I I do have it in some of the videos that I've I've shown a keyless, secret, secure secret remote access before. But, yeah, to answer your question, yeah, it's there. They have it. And then and the nice part about that, I will say, is it's still using, like, it is one unified product. Right? This is not like something that we bought elsewhere. And so when you set up, like, rotated secrets to use with your applications, those same exact rotated secrets can be used with our secure remote access. So you don't have to configure humans and people separately. You can configure them all in one place and and manage the access roles for that in the same place too. Yep. There you go. So here's a, a dynamic secret, and you can just configure it for secure remote access, and that'll come with the session recording and all that jazz. Yep. Alright. What else? Well, that one's done. Yeah. Go ahead. You wanted to talk about the vault agent? I thought you were. I think the the secure one access. No. I I we the I think the closest we have to the vault agent would be, the secrets injector that I talked about, although that's one specifically for Kubernetes, is is the short answer to that. Yep. K. Alright. So we are at time. Yeah. We have I have quite a few left. So what we'll do is I think we can we can answer those, offline. I wanna be respectful for of everybody's time. So really thankful for everybody who joined us today. I think this was a very cool session. We got to talk about both HashiCorp and Akeyless and to show what, Akeyless has to offer. So thank you, everybody. This, will be recorded. So if you had to leave or somebody had to leave, you'll see the recordings later. Alright. So thanks, everybody. Thank you.