Identity & Access Security
Identity and access security tools centralize secrets storage, manage authentication and authorization, and monitor for privilege drift and credential exposure across cloud and on-premises systems.
| Tool | License | Platforms | Pricing | Action |
|---|---|---|---|---|
| HashiCorp Boundary | BUSL-1.1 | Linux, macOS, Windows | Free / Commercial | Profile→ |
| HashiCorp Vault | BUSL-1.1 | Linux, macOS, Windows | Free / Commercial | Profile→ |
| Keycloak | Apache-2.0 | Linux, Windows | Free / Commercial | Profile→ |
| Teleport | AGPL-3.0-or-later (core); Apache-2.0 (API); modified Apache-2.0 (community builds); commercial (enterprise) | Linux, macOS, Windows | Free / Commercial | Profile→ |
Tools in Identity & Access Security
HashiCorp Boundary
Free / CommercialIdentity-aware proxy that brokers just-in-time, least-privileged access to hosts and critical systems without distributing credentials or exposing private networks.
HashiCorp Vault
Free / CommercialSecrets management, encryption as a service, and identity-based access platform with dynamic credentials, PKI, and audit logging.
Keycloak
Free / CommercialOpen-source IAM suite providing single sign-on, user federation, fine-grained authorization, and OAuth2/OpenID Connect support.
Teleport
Free / CommercialIdentity-aware access platform that issues short-lived certificates for SSH, Kubernetes, database, RDP, and web application access with session recording and audit.
Frequently Asked Questions
What is Identity & Access Security?→
Identity and access security tools centralize secrets storage, manage authentication and authorization, and monitor for privilege drift and credential exposure across cloud and on-premises systems.
What topics does the Identity & Access Security category cover?→
Secrets Management, Identity & Access Management (IAM), Privileged Access Management (PAM), Identity Threat Detection & Response (ITDR), Zero Trust Access Proxies
About Identity & Access Security
Identity and access security tools manage how users, services, and machines authenticate to systems and what they can access once authenticated. The category covers several areas. Secrets management platforms like HashiCorp Vault centralize storage of API keys, database credentials, and certificates, replacing hardcoded secrets with dynamic, short-lived credentials. Identity and access management (IAM) systems like Keycloak provide single sign-on, OAuth2, and OpenID Connect authentication for applications. Identity-aware proxies like Teleport and HashiCorp Boundary broker access to SSH, Kubernetes, and database resources without exposing credentials or private networks. Privileged access management tools monitor and control administrative sessions, recording activity for audit. Identity threat detection and response (ITDR) tools monitor identity systems for compromise indicators like anomalous login patterns and privilege escalation. The category has grown with cloud adoption, since cloud environments introduce dynamic infrastructure where static credentials and VPN-based access models do not scale. Tools in this category overlap with cloud-native security for cloud IAM auditing and with red team tools for testing access controls.
Covered Topics & Disciplines
Related Security Categories
CSPM scanners, container and Kubernetes policy engines, and cloud configuration auditing tools.
Compliance automation frameworks, SCAP policy scanners, and risk management platforms.
Adversary emulation platforms, C2 frameworks, and atomic test libraries for authorized red team operations.