CyberArk Conjur
CyberArk Conjur is an open source secrets management platform that authenticates, authorizes, and audits non-human identities across DevOps tools, containers, and cloud environments. It serves DevOps engineers, platform teams, and security teams via a community-led open source model with an enterprise upgrade path.
- Company typePrivate
- Founded-
- HeadquartersBoston, United States
- Headcount—
- GTM typeB2B
- OfferingSoftware
What CyberArk Conjur does
CyberArk Conjur is an open source secrets management platform that provides authentication, granular Role-Based Access Control (RBAC), and immutable audit trails for non-human identities — containers, applications, services, and cloud workloads — across DevOps toolchains and cloud environments. The platform's core architecture centers on a policy-as-code model in which security policies are written as YAML files, checked into source control, and loaded onto the Conjur server, enabling version control, peer review, and automated enforcement of access rules. Notable technical components include the Secretless Broker (which allows applications to connect to protected resources without handling credentials directly, reducing attack surface), the Summon CLI (which injects secrets as environment variables from multiple providers), and a REST API with SDKs for Ruby, Python, and Java. Conjur integrates natively with major DevOps and cloud platforms — Kubernetes, OpenShift, Jenkins, Ansible, Puppet, Terraform, Cloud Foundry, AWS, Azure, and GCP — and supports native authentication of workloads using platform-native attributes such as AWS IAM roles, Kubernetes service account JWTs, and Azure Managed Identities.
The business model is a hybrid open source / freemium structure: Conjur Open Source is distributed free of charge via GitHub for community and self-service users, while the enterprise version — CyberArk Application Access Manager for DevOps — is sold as a subscription through CyberArk's direct enterprise sales motion and includes additional features, support, and upgrades. Go-to-market is community-led, with developer relations, technical documentation, conference presence (notably KubeCon), and a Discourse community forum serving as the primary acquisition channels; pricing is quote-based and not publicly disclosed. The platform serves DevOps engineers, container/platform engineering teams, security and compliance teams, and cloud-native platform teams whose primary pain points are secrets sprawl across CI/CD pipelines, hard-coded credentials, weak container identity verification, and inconsistent security policies across multi-cloud environments. As of 2026, CyberArk — Conjur's parent — was acquired by Palo Alto Networks, positioning Conjur within a larger strategic security portfolio.
CyberArk Conjur firmographics
Firmographics- Name
- CyberArk Conjur
- Legal name
- CyberArk Software Ltd.
- Website
- https://conjur.org
- Company type
- Private
- Operating status
- Operating
- Short description
- CyberArk Conjur is an open source secrets management platform that authenticates, authorizes, and audits non-human identities across DevOps tools, containers, and cloud environments. It serves DevOps engineers, platform teams, and security teams via a community-led open source model with an enterprise upgrade path.
- Ownership category
- akta.pro rank
CyberArk Conjur industry classification
Industry- Product category
- Secrets Management / Privileged Access Management
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Secrets Management (Passwords, API Keys, Tokens) (HDADAFAD)
Keywords
Where CyberArk Conjur is headquartered
LocationHeadquarters
- HQ city
- Boston
- HQ country
- United States
- HQ region
- North America
Markets served
CyberArk Conjur business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Conjur Open Source: Free open source version of secrets management platform distributed via GitHub with community support. Available to all users at no cost.
- CyberArk Application Access Manager for DevOps: Enterprise version of Conjur with additional features, support, and upgrades. Sold as part of CyberArk's privileged access management portfolio.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Conjur Open Source - Free tier |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels8 records
CyberArk Conjur product offering
Product offeringCore offering
CyberArk Conjur is an open source secrets management platform that securely authenticates, controls, and audits non-human access across DevOps tools, applications, containers, and cloud environments via policy-based RBAC and security policy as code. The product is offered as a free open source version (Conjur Open Source) with an upgrade path to the enterprise-tier CyberArk Application Access Manager for DevOps, which adds enterprise features, support, and scalability for production deployments.
Product overview
CyberArk Conjur is an open source secrets management platform that consists of a core Conjur Open Source engine and multiple open source integrations and utilities. The core platform provides secure authentication, RBAC-based access control, and audit trails for managing secrets across tools, applications, containers, and cloud environments. Key components include the Secretless Broker (which isolates applications from credentials), Summon (CLI tool for injecting secrets), and official integrations for Jenkins, Ansible, Puppet, Terraform, Kubernetes, Cloud Foundry, and other DevOps tools. The enterprise offering, CyberArk Application Access Manager for DevOps, builds on the open source foundation with additional enterprise features and support.
Differentiator
Problem solved
Functional benefit
Brands
- Secretless Broker: An open source feature that enables applications to securely connect to databases, services and other protected resources without fetching or managing secrets directly.
- CyberArk Application Access Manager
Products and services
- CyberArk Conjur Open Source
Quantifiable outcome
- Reduce security islands by centralizing secrets management across multi-cloud and multi-tool environments
- +1 more outcomes
Companies that use CyberArk Conjur
Customer profileSegments4 records
Ideal customer profiles2 records
CyberArk Conjur technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration10 records
Feature9 records
CyberArk Conjur partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core.
- Ansible (Red Hat)coreNative integration with Ansible automation platform. Conjur provides secrets lookup plugin and conjur-host-identity role for secure Ansible deployments. Supports API key, AWS IAM, Azure, GCP authenticators for Ansible nodes.
- AWScoreAWS IAM Authenticator enables EC2 instances and Lambda functions to use their AWS IAM role for authentication. Conjur available in AWS Marketplace. Native integration with AWS services.
- Cloud FoundrycoreConjur Service Broker and Buildpack for Cloud Foundry enable applications deployed in CF spaces to authenticate with Conjur and retrieve secrets. Provides unique identity to each application.
- JenkinscoreConjur Secrets plugin for Jenkins enables authentication and secret retrieval for pipeline code or Freestyle projects. Supports JWT and API key authentication with credential inheritance.
- KubernetescoreNative Kubernetes integration enables secure secrets distribution to pods using Kubernetes authenticator (certificate-based or JWT-based). Supported on GKE, EKS, AKS, OpenShift, and other distributions.
- OpenShift (Red Hat)coreFull integration with Red Hat OpenShift including OpenShift Secrets Management Operator for Conjur Follower. Supports OpenShift v4.16-4.20 with cert-based and JWT-based authentication.
- PuppetcoreOfficial Puppet module (v3) for automatic workload identity configuration. Enables workloads to use their identity for authenticated calls to Conjur. Distributed via Puppet Forge.
- Terraform (HashiCorp)coreTerraform provider for fetching secrets from Conjur. Integration via Secrets Manager Terraform Provider or with Summon utility for injecting secrets as environment variables.
- Google Cloud Platform (GCP)coreGCP authenticator for Conjur and availability in GCP Marketplace. KubeCon demos showing Conjur on GKE. GKE Workload Identity Federation integration documented.
- AzurecoreAzure authenticator for Conjur. Integration with Azure Serverless Functions and Managed Identities. Supports Azure workload identity authentication.
- Kubernetes Secrets Vault ProviderscoreSecretless Broker works with Kubernetes Secrets vaults and CyberArk Application Access Manager's Dynamic Access Provider for multi-vault support.
Recent moves5 records
Expansion highlights4 records
CyberArk Conjur competitors and assessment
Company assessmentEmerging players
- StrongDM: Access platform providing just-in-time access to databases, servers, and Kubernetes clusters with secrets management capability. Targets a broader privileged access workflow that intersects with Conjur's non-human identity use cases.
- Pulumi ESC (Environments, Secrets, and Configuration): Pulumi's environment and secrets management service that integrates secrets retrieval into infrastructure-as-code workflows. Overlaps with Conjur's Terraform integration story for teams standardizing on Pulumi as their IaC tool.
- Keeper Secrets Manager: Enterprise password and secrets management offering from Keeper Security, expanding from human credential vaulting to machine-to-machine secrets. Competes for enterprise secrets management budgets alongside Conjur.
Broad incumbents
- AWS Secrets Manager: Cloud-provider-native secrets management service from AWS, tightly integrated with EC2, Lambda, RDS, and other AWS services. Represents the primary alternative for single-cloud AWS deployments that might otherwise adopt Conjur.
- Google Secret Manager: GCP's managed secrets service with native IAM integration for Google Cloud workloads. Competes for the GCP-native segment of the same cloud workloads Conjur's GCP authenticator targets.
- Azure Key Vault: Microsoft's managed secrets store integrated with Azure services, Active Directory, and Azure DevOps. Serves the same secrets-management function for Azure-centric enterprises as Conjur does in multi-cloud environments.
Direct peers
- Infisical: Open source secrets management platform with a freemium model and developer-first UX, directly comparable to Conjur Open Source. Targets similar use cases (CI/CD secrets, Kubernetes secrets, environment variables) with a modern community-led GTM.
- Akeyless: SaaS-based secrets management and zero-trust access platform targeting enterprise DevOps teams with Vault-like functionality delivered as a managed service. Competes directly with CyberArk Application Access Manager for DevOps for enterprise contracts.
- HashiCorp Vault: The leading open source and enterprise secrets management platform, offering centralized secrets storage, dynamic secrets, and PKI integration across the same DevOps and cloud-native ecosystem that Conjur serves. Vault is the most direct open source competitor for Conjur's developer and platform engineering audience.
- Doppler: Developer-focused secrets management platform targeting the same DevOps and platform engineering personas as Conjur, with strong CI/CD integrations and sync to cloud targets. Positions itself as simpler alternative for cloud-native teams.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
CyberArk Conjur social profiles
Digital presenceCyberArk Conjur financial estimates
Financial estimateRevenue estimate
Valuation estimate
CyberArk Conjur leadership team
Management profileNumber of profiles
Profiles1 record
CyberArk Conjur funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CyberArk Conjur M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CyberArk Conjur
What does CyberArk Conjur do?
CyberArk Conjur is an open source secrets management platform that securely authenticates, controls, and audits non-human access across DevOps tools, applications, containers, and cloud environments via policy-based RBAC and security policy as code. The product is offered as a free open source version (Conjur Open Source) with an upgrade path to the enterprise-tier CyberArk Application Access Manager for DevOps, which adds enterprise features, support, and scalability for production deployments.
Is CyberArk Conjur a public or private company?
CyberArk Conjur is a private company. It is classified as corporate owned and is currently operating.
When was CyberArk Conjur founded?
CyberArk Conjur was founded in -1.
Where is CyberArk Conjur based?
CyberArk Conjur is headquartered in Boston, United States, in the North America region.
How does CyberArk Conjur make money?
Two revenue lines are on record. Conjur Open Source is the primary driver. The others are cyberArk Application Access Manager for DevOps.
Who are CyberArk Conjur's main competitors?
Emerging players on record are StrongDM, Pulumi ESC (Environments, Secrets, and Configuration) and Keeper Secrets Manager. Broad incumbents are AWS Secrets Manager, Google Secret Manager and Azure Key Vault. Direct peers are Infisical, Akeyless, HashiCorp Vault and Doppler.
Does CyberArk Conjur have an API?
Yes. The Conjur API provides REST API for controlling and manipulating Conjur software, including managing roles, privileges, policy, and secrets. The CLI Client implements the REST API as an alternate interface. SDKs available for Ruby, Python, and Java client libraries. Developer documentation is at docs.conjur.org/Latest/en/Content/API.
What industry is CyberArk Conjur in?
CyberArk Conjur's product category is Secrets Management / Privileged Access Management. Its primary akta.pro industry code is HDADAFAD, Secrets Management (Passwords, API Keys, Tokens). Its NAICS code is 54151 and its SIC code is 7372.