Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Ensure the protection, storage, and stringent management of tokens, passwords, certificates, and encryption keys that are essential for safeguarding sensitive information, utilizing options like a user interface, command-line interface, or HTTP API. Strengthen applications and systems through machine identity while automating the processes of credential issuance, rotation, and additional tasks. Facilitate the attestation of application and workload identities by using Vault as a reliable authority. Numerous organizations often find credentials embedded within source code, dispersed across configuration files and management tools, or kept in plaintext within version control systems, wikis, and shared storage. It is crucial to protect these credentials from being exposed, and in the event of a leak, to ensure that the organization can swiftly revoke access and remedy the situation, making it a multifaceted challenge that requires careful consideration and strategy. Addressing this issue not only enhances security but also builds trust in the overall system integrity.
Description
Knox serves as a secret management platform designed for the secure storage and rotation of sensitive information such as secrets, keys, and passwords utilized by various services. Within Pinterest, a multitude of keys and secrets are employed for diverse functions, including signing cookies, encrypting sensitive data, securing the network through TLS, accessing AWS machines, and facilitating communication with third-party services, among others. The risk of these keys being compromised posed significant challenges, as the process of rotation typically required a deployment and often necessitated changes to the codebase. Previously, keys and secrets at Pinterest were stored in Git repositories, leading to their replication across the company's infrastructure and presence on numerous employee laptops, which made tracking access and auditing who had permission to use these keys virtually impossible. To address these issues, Knox was developed with the intention of simplifying the process for developers to securely access and utilize confidential secrets, keys, and credentials. It also ensures the confidentiality of these sensitive elements while providing robust mechanisms for key rotation in the event of a security breach, thereby enhancing overall security practices. By implementing Knox, Pinterest aims to streamline secret management processes while fortifying its defenses against potential vulnerabilities.
API Access
Has API
Yes
API Access
Has API
Yes
Integrations
AWS Marketplace
Yes
Brainboard
Yes
Clutch
Yes
ElectroNeek
Yes
Galgos AI
Yes
IBM Cloud Hyper Protect Crypto Services
Yes
Juniper Apstra
Yes
Keyfactor EJBCA
Yes
MongoDB
Yes
Netdata
Yes
Integrations
AWS Marketplace
No
Brainboard
No
Clutch
No
ElectroNeek
No
Galgos AI
No
IBM Cloud Hyper Protect Crypto Services
No
Juniper Apstra
No
Keyfactor EJBCA
No
MongoDB
No
Netdata
No
Pricing Details
No price information available.
Free Trial
No
Free Version
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
Yes
Deployment
Web-Based
No
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
Yes
Mac
Yes
Linux
Yes
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
HashiCorp
Founded
2012
Country
United States
Website
www.vaultproject.io
Vendor Details
Company Name
Founded
2009
Country
United States
Website
github.com/pinterest/knox
Product Features
Data Security
Alerts / Notifications
No
Antivirus/Malware Detection
No
At-Risk Analysis
No
Audits
No
Data Center Security
No
Data Classification
No
Data Discovery
No
Data Loss Prevention
No
Data Masking
No
Data-Centric Security
No
Database Security
No
Encryption
No
Identity / Access Management
No
Logging / Reporting
No
Mobile Data Security
No
Monitor Abnormalities
No
Policy Management
No
Secure Data Transport
No
Sensitive Data Compliance
No
Encryption
Central Policy Enforcement
No
Drag & Drop UI
No
Email Encryption
No
Encryption Key Management
Yes
Endpoint Encryption
No
File Compression
No
File Encryption
Yes
Full Disk Encryption
Yes
Public Key Cryptography
Yes
Tokenization / Data Masking
Yes
Product Features
Privileged Access Management
Application Access Control
No
Behavioral Analytics
No
Credential Management
No
Endpoint Management
No
For MSPs
No
Granular Access Controls
No
Least Privilege
No
Multifactor Authentication
No
Password Management
No
Policy Management
No
Remote Access Management
No
Threat Intelligence
No
User Activity Monitoring
No