Till and secret managers solve different layers

Till is a hosted request-control layer for supported AI APIs. HashiCorp Vault and AWS Secrets Manager manage general secrets. Many teams can use them together.

Scroll horizontally to compare all three products.

Responsibility
Till Hosted AI request controls
HashiCorp Vault Secrets and identity
AWS Secrets Manager Managed AWS secrets
Primary role Control and account for requests to supported AI providers Centralize secrets, identities, encryption, and privileged access Store, retrieve, and rotate application secrets in AWS
What the workload receives A scoped Till bearer token that does not reveal provider credentials A Vault token, secret, or generated credential according to the configured engine A retrieved or rotated secret according to the application's integration
AI request-path controls Activation ceiling plus optional token, spend, expiry, and IP controls Not an AI request proxy; compose separate application or gateway controls Not an AI request proxy; compose separate application or gateway controls
AI provider routing 12 built-in adapters with provider-agnostic scoped tokens Integrate providers through your own plugins, applications, or gateways Integrate providers through your own applications or AWS services
Secret handling Provider connections encrypted at rest; complete scoped tokens are not stored Secrets and generated credentials are managed through configurable secrets engines Secret values and versions are stored encrypted and retrieved at runtime
Operating model Till-hosted controlled beta Self-managed Vault or HashiCorp's managed HCP Vault offering AWS-managed regional service
Evidence and reporting Scoped-key usage counters and dashboard; a complete audit log is not yet available Configurable audit devices record Vault requests and responses Integrates with AWS logging and monitoring services

When to use each solution

Till

Best for teams that need bounded credentials and request-level accounting for supported AI APIs.

  • Sandboxing agent workloads
  • Contractor/freelancer API access
  • Demo environments with limits
  • Per-project budget allocation
  • Bounding estimated AI spend

HashiCorp Vault

For organizations centralizing secret, identity, encryption, and privileged-access workflows across varied infrastructure.

  • Database credential rotation
  • PKI certificate management
  • SSH key management
  • Encryption as a service
  • Multi-cloud secrets

AWS Secrets Manager

For applications that need AWS-managed secret storage, retrieval, access control, and supported rotation workflows.

  • RDS database credentials
  • AWS service integrations
  • Lambda function secrets
  • ECS/EKS deployments
  • CloudFormation templates

The key difference

HashiCorp describes Vault as centralized secret and privileged-access management. AWS describes Secrets Manager as a service for managing, retrieving, and rotating secrets throughout their lifecycle.

Till is a credential proxy — it creates bounded, disposable keys that enforce limits at the API call level. Provider connections are encrypted at rest and selected automatically; scoped tokens do not reveal provider credentials.

Till does not replace a general-purpose secret manager, cloud IAM, or provider-side controls. Use Till when its supported AI request controls are the missing layer; keep Vault or AWS Secrets Manager where you need their broader secret-management capabilities.

Request controlled-beta access

New accounts are manually onboarded while verified-email signup is being completed.

Request beta access