Alright, I've been in the trenches with both platforms over the last few years, managing vaults for different teams. My hot take: for pure ease of management, Thycotic Secret Server (now Delinea Secret Server) wins for me.
Its web interface just feels more intuitive, especially for onboarding new team members. The discovery and onboarding of secrets feels more automated. BeyondTrust Password Safe is incredibly powerful, no doubt, but I've found its setup and policy granularity comes with a steeper learning curve. The initial configuration took us longer to get "just right."
For teams that need to move fast and want admins to get up to speed quickly, Secret Server has the edge. Curious if others have had the same experience, or if I'm missing some newer Password Safe workflows? Happy testing!
Another tool to try!
I'm Juliet, a marketing ops lead at a 150-person SaaS company. We manage a few hundred developer and vendor secrets, and we've been running Delinea Secret Server in production for about a year.
Here's my breakdown based on our evaluation:
**Target Fit**: Secret Server felt aimed at mid-sized companies like ours, while Password Safe seemed geared for larger enterprises. Our 3-person infosec team could handle Secret Server.
**Pricing Visibility**: Secret Server had clearer upfront pricing. Password Safe required a full sales engagement and felt like it was priced for larger deployments.
**Setup Time**: We had Secret Server operational, with key integrations like our IDP and a handful of servers, in under two weeks. The BeyondTrust pilot felt more involved from the start.
**Daily Management**: The "Require Approval" workflow in Secret Server is straightforward for one-off access requests. Reviews of Password Safe suggested more powerful policy engines, but we didn't need that granularity.
I'd recommend Secret Server for teams under 200 people that need a functional vault without a lengthy implementation. For a clearer choice, tell us your team size and if you need strict regulatory compliance (like SOX) or just basic secret rotation.
Interesting you mention the "geared for larger enterprises" point. I've seen both platforms deployed at very different scales.
The claim that Password Safe's policy engine is just "more powerful" undersells it. The complexity isn't a bonus feature, it's the product. If you aren't managing thousands of secrets across dozens of regulated subsidiaries with distinct ownership rules, you're just paying for UI clutter. Secret Server's relative simplicity is often just the absence of cruft you'd never use.
That said, for a 150-person shop with a few hundred secrets, your choice is obvious. You'd be buying a tank to go to the grocery store. The real question is what happens at 400 people, or when a big compliance framework hits. Does Secret Server's model scale cleanly, or do you hit a wall and have to migrate?
You're right about the tank for groceries comparison. I've seen teams hit that wall around the 500-secret mark, especially when they start needing granular, policy-based access for contractors or third parties.
The migration cost from a simpler system is brutal. It's not just the new license, it's the man-hours to re-map all those access patterns. Makes that "easy setup" a false economy if you're growing quickly.
Did anyone run a proper break-even on the extra admin hours vs the more complex platform's upfront cost?
Show me the bill