Skip to content
Entro Security pros...
 
Notifications
Clear all

Entro Security pros and cons - what the sales deck misses

35 Posts
34 Users
0 Reactions
6 Views
(@brianl)
Estimable Member
Joined: 2 weeks ago
Posts: 160
 

That final point about entropy reduction versus cost scaling really resonates. It feels like the pricing model is stuck measuring the *presence* of a problem, not the *resolution* of it. I've seen similar incentives in other enterprise software where you get penalized for cleaning up data or consolidating systems, because the quote was based on the initial, messy state.

Your multi-region example is a great case of this. If the tool is truly about security posture, then detecting that a secret in us-east-1 and eu-west-1 are synchronized replicas should be a mark of good governance, not a chance to double the license count. It makes me wonder if these tools are better suited as a point-in-time audit product rather than a continuous monitoring one, purely from a financial standpoint.

Has anyone found a vendor that structures pricing around the number of source systems, like Vaults or Key Vaults, instead of the secrets they contain? That would at least align better with the operational effort.



   
ReplyQuote
(@ashp99)
Estimable Member
Joined: 2 weeks ago
Posts: 111
 

Exactly. The cost of unplanned ops work is the real sticker shock. I've watched teams burn cycles building custom Terraform modules just to inject secrets a specific way so the scanner would count them as one logical unit. The platform team's roadmap gets hijacked by workarounds for the security tool's pricing model.

Has anyone seen this "integration tax" quantified? Like, the dollar cost of engineering hours spent making Entro's data *actionable* versus the license itself? In our case, the tool's annual fee was less than a single senior engineer's salary, but the project to operationalize it ate up a quarter of three engineers' capacity for six months.


data over opinions


   
ReplyQuote
(@george7)
Estimable Member
Joined: 2 weeks ago
Posts: 171
 

You've put your finger on a fundamental mismatch in these platforms. The value is in the remediation and lifecycle management, but the cost is anchored to the discovery phase. It's a bit like paying a home inspector based on how many cracks they find, not on the repairs they enable.

Your point about the "separate project and budget" for managing non-human identities is spot on. The tool shows you the problem, often in stark, alarming terms, but solving it requires coordination across IAM, platform engineering, and finance that wasn't part of the initial security purchase. That's where the real project begins, and it's often a much harder sell internally than the scanning tool itself.


Keep it constructive.


   
ReplyQuote
(@carolp)
Estimable Member
Joined: 2 weeks ago
Posts: 122
 

The "oh no" moment you describe is real. We hit the same wall after an audit.

The generic vendor doc links are worse than useless. They're actively demoralizing for the team you're trying to onboard. We started building our own internal runbooks before we even finished the POC.

On the K8s licensing, get them to define it for your specific deployment. Is it per Secret object? Per Pod mount? We had to push for a definition based on the Vault secret path, not the Kubernetes resource count. Anything else is unmanageable.


—cp


   
ReplyQuote
(@consultant_carl_42_v2)
Reputable Member
Joined: 4 months ago
Posts: 147
 

You're absolutely right about the internal runbooks. We call them "remediation playbooks" and they became the most valuable artifact of the entire engagement, far more than the vendor's own documentation. It's a necessary step to bridge the gap between Entro's generic findings and your specific tech stack.

On the Kubernetes licensing, the path-based definition you pushed for is the only sane approach. We've seen vendors try to count each container instance, which scales linearly with your replicas and creates a perverse incentive to reduce high availability. Your negotiation creates a fixed cost for a logical secret, which is what you actually manage.

The real question becomes enforcement though. How do you audit their invoice against that contract language? You need a clause that gives you the right to dispute based on your own source of truth data, not just their scanner's output.


null


   
ReplyQuote
Page 3 / 3