AWS Secrets Manager
AWSSecurityFully managed service to store, rotate, and audit secrets such as database credentials, API keys, and OAuth tokens with native rotation Lambda integrations for RDS, Redshift, and DocumentDB
Attributes
- SLA Uptime
- 99.9%
- Encryption
- Yes
- Multi Region
- Yes
Sub-services (3)
Secrets
Versioned encrypted secret values stored under a resource ARN
Automatic Rotation
Lambda-driven rotation schedules for database and custom secrets
Multi-Region Replication
Primary/replica replication of secrets across AWS regions
Compliance & Certifications
This service is attested for the following frameworks. Always verify with the provider before relying on a specific compliance posture.
Where this runs
Sovereign regions (5)
- AWS GovCloud (US-East) · AshburnAWS GovCloud (US)
- AWS GovCloud (US-West) · HillsboroAWS GovCloud (US)
- AWS European Sovereign Cloud (Brandenburg) · BrandenburgAWS European Sovereign Cloud
- China (Beijing) · BeijingAWS China (Sinnet)
- China (Ningxia) · YinchuanAWS China (NWCD)
Commercial regions (33)
Europe (8)
- Europe (Paris)
- Europe (Frankfurt)
- Europe (Ireland)
- Europe (Milan)
- Europe (Spain)
- Europe (Stockholm)
- Europe (Zurich)
- Europe (London)
North America (7)
- Canada West (Calgary)
- Canada (Central)
- Mexico (Central)
- US East (N. Virginia)
- US West (Oregon)
- US East (Ohio)
- US West (N. California)
South America (1)
- South America (São Paulo)
Asia (11)
- Asia Pacific (Hong Kong)
- Asia Pacific (Hyderabad)
- Asia Pacific (Mumbai)
- Asia Pacific (Jakarta)
- Asia Pacific (Osaka)
- Asia Pacific (Tokyo)
- Asia Pacific (Malaysia)
- Asia Pacific (Singapore)
- Asia Pacific (Seoul)
- Asia Pacific (Taipei)
- Asia Pacific (Thailand)
Oceania (2)
- Asia Pacific (Melbourne)
- Asia Pacific (Sydney)
Middle East (3)
- Middle East (Bahrain)
- Israel (Tel Aviv)
- Middle East (UAE)
Africa (1)
- Africa (Cape Town)
Tags
Equivalent services on other platforms
Centralised vault for cryptographic keys, secrets, and certificates with HSM-backed keys, managed certificate renewal, and RBAC or access-policy enforcement
Fully managed secret storage with automatic replication across regions, VPC Service Controls integration, CMEK encryption, version history, per-secret IAM, and rotation via Cloud Scheduler plus Cloud Run hooks — used by GKE, Cloud Run, and Compute Engine workloads
Centralised key and secret management service with HSM-backed symmetric and asymmetric keys, automatic rotation, and envelope encryption for OCI resources