Till and secret managers solve different layers
Till is a hosted request-control layer for supported AI APIs. HashiCorp Vault and AWS Secrets Manager manage general secrets. Many teams can use them together.
Scroll horizontally to compare all three products.
| Responsibility |
Till
Hosted AI request controls
|
HashiCorp Vault
Secrets and identity
|
AWS Secrets Manager
Managed AWS secrets
|
|---|---|---|---|
| Primary role | Control and account for requests to supported AI providers | Centralize secrets, identities, encryption, and privileged access | Store, retrieve, and rotate application secrets in AWS |
| What the workload receives | A scoped Till bearer token that does not reveal provider credentials | A Vault token, secret, or generated credential according to the configured engine | A retrieved or rotated secret according to the application's integration |
| AI request-path controls | Activation ceiling plus optional token, spend, expiry, and IP controls | Not an AI request proxy; compose separate application or gateway controls | Not an AI request proxy; compose separate application or gateway controls |
| AI provider routing | 12 built-in adapters with provider-agnostic scoped tokens | Integrate providers through your own plugins, applications, or gateways | Integrate providers through your own applications or AWS services |
| Secret handling | Provider connections encrypted at rest; complete scoped tokens are not stored | Secrets and generated credentials are managed through configurable secrets engines | Secret values and versions are stored encrypted and retrieved at runtime |
| Operating model | Till-hosted controlled beta | Self-managed Vault or HashiCorp's managed HCP Vault offering | AWS-managed regional service |
| Evidence and reporting | Scoped-key usage counters and dashboard; a complete audit log is not yet available | Configurable audit devices record Vault requests and responses | Integrates with AWS logging and monitoring services |
When to use each solution
Till
Best for teams that need bounded credentials and request-level accounting for supported AI APIs.
- Sandboxing agent workloads
- Contractor/freelancer API access
- Demo environments with limits
- Per-project budget allocation
- Bounding estimated AI spend
HashiCorp Vault
For organizations centralizing secret, identity, encryption, and privileged-access workflows across varied infrastructure.
- Database credential rotation
- PKI certificate management
- SSH key management
- Encryption as a service
- Multi-cloud secrets
AWS Secrets Manager
For applications that need AWS-managed secret storage, retrieval, access control, and supported rotation workflows.
- RDS database credentials
- AWS service integrations
- Lambda function secrets
- ECS/EKS deployments
- CloudFormation templates
The key difference
HashiCorp describes Vault as centralized secret and privileged-access management. AWS describes Secrets Manager as a service for managing, retrieving, and rotating secrets throughout their lifecycle.
Till is a credential proxy — it creates bounded, disposable keys that enforce limits at the API call level. Provider connections are encrypted at rest and selected automatically; scoped tokens do not reveal provider credentials.
Till does not replace a general-purpose secret manager, cloud IAM, or provider-side controls. Use Till when its supported AI request controls are the missing layer; keep Vault or AWS Secrets Manager where you need their broader secret-management capabilities.
Request controlled-beta access
New accounts are manually onboarded while verified-email signup is being completed.
Request beta access