Cybersecurity · head to head
HashiCorp Boundary vs Semperis

HashiCorp Boundary
Cybersecurity
Identity-aware session broker for infrastructure access without distributing credentials
- From
- Free
- Rated
- -

Semperis
Cybersecurity
Identity threat detection and Active Directory forest recovery for AD, Entra ID and Okta, from a privately held US vendor.
- From
- On request
- Rated
- -
The short version
- Only HashiCorp Boundary has a free tier, so it costs nothing to try first.
- Each has a real cost: HashiCorp Boundary hashiCorp was acquired by IBM in February 2025 and Enterprise licensing now runs through IBM Passport Advantage; IBM has already retired HCP Vault Secrets, so Boundary's roadmap depends on IBM portfolio decisions rather than HashiCorp's own product strategy.; Semperis scope is limited to Active Directory, Entra ID and Okta, so an organisation whose critical identity lives elsewhere gets little from it, and the recovery value declines in direct proportion to how much has already moved off on-premises AD.
- They diverge on capability: HashiCorp Boundary covers Identity-based access, Semperis covers Active Directory Forest Recovery.
- Prices and features above were last checked on 31 August 2026.
Where they differ
Only the attributes on which HashiCorp Boundary and Semperis actually diverge.
| Attribute | HashiCorp Boundary | Semperis |
|---|---|---|
| Starting price | Free | On request |
| Pricing model | Open source, no licence fee | quote |
| Free tier | Yes | No |
| Platforms | Linux, macOS, Windows, Web | Web |
Identical on both: user rating (Not yet rated), category (Cybersecurity).
What each one covers
Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.
Only in HashiCorp Boundary
- Identity-based access
- Just-in-time credentials
- Dynamic host catalogues
- Session recording
- Transparent sessions
- Multi-hop workers
- Audit logging
- Terraform provider
Only in Semperis
- Active Directory Forest Recovery
- Malware-free restore
- Replication-stream monitoring
- Automated rollback
- Attack indicator scoring
- Entra ID and Okta coverage
- Purple Knight
- Forest Druid
What people use each for
The jobs each tool is most often brought in to do.
HashiCorp Boundary
- A platform team replacing shared SSH keys and a bastion host so that leavers lose access the moment they are removed from the identity providernot Semperis
- Granting contractors time-boxed database access without ever issuing them a credential they could keepnot Semperis
- An estate where autoscaling replaces hosts continuously and a static access list is always out of datenot Semperis
- Producing session recordings as evidence for an audit that requires proof of who touched production and what they rannot Semperis
Semperis
- An organisation that cannot answer an auditor or insurer asking how long it would take to rebuild Active Directory after a destructive attacknot HashiCorp Boundary
- Post-incident recovery where domain controllers are compromised and restoring from system-state backup would reintroduce the attacker's footholdnot HashiCorp Boundary
- Continuous detection of privileged group changes and directory-level tampering that domain controller security logs missnot HashiCorp Boundary
- Hybrid estates where AD, Entra ID and Okta all matter and no single tool currently shows changes across the threenot HashiCorp Boundary
Where each one falls short
Documented limitations, not opinions. Every one is a constraint you would hit in normal use.
HashiCorp Boundary
- HashiCorp was acquired by IBM in February 2025 and Enterprise licensing now runs through IBM Passport Advantage; IBM has already retired HCP Vault Secrets, so Boundary's roadmap depends on IBM portfolio decisions rather than HashiCorp's own product strategy.
- Enterprise pricing is not published anywhere, and the features most organisations actually need for compliance, notably session recording, are Enterprise only, so the free community edition is rarely the version you end up buying.
- It solves access to infrastructure, not to applications; browser-based internal tools, SaaS admin consoles and APIs need a separate control, so Boundary is one component of a zero-trust programme rather than the whole thing.
- Running it yourself means operating controllers, worker nodes and a Postgres database in a highly available configuration, and if that control plane is down nobody can reach production, which makes it a new critical dependency.
- It is materially easier to adopt if you already run Vault and Terraform; teams without that ecosystem face a steeper learning curve than a device-based mesh product like Tailscale, for a similar access outcome.
Semperis
- Scope is limited to Active Directory, Entra ID and Okta, so an organisation whose critical identity lives elsewhere gets little from it, and the recovery value declines in direct proportion to how much has already moved off on-premises AD.
- The licence buys tooling, not a proven runbook: forest recovery is only worth what your last rehearsal demonstrated, and a plan that has never been executed end to end in a lab is an untested assumption regardless of what was purchased.
- It overlaps with backup and directory management products from Quest, Veeam, Commvault and others, so the buyer must argue internally why a dedicated product is needed alongside a backup contract that already claims to protect Active Directory.
- Running Directory Services Protector well requires someone who understands AD internals, replication metadata and Tier 0 attack paths, and without that person the alerts on privileged changes are either ignored or auto-reverted in ways that break legitimate administration.
- Licensing is driven by identity object counts, so directories carrying years of stale user accounts and service principals pay for objects that should have been deleted, and the cleanup project that would reduce the bill is the one nobody has time for.
Pricing, plan by plan
HashiCorp Boundary
Free- Boundary Community EditionFree
- MPL 2.0 open source
- Self-hosted controllers and workers
- Identity-based target access
- Boundary Enterprise$undefined/year
- Session recording and playback
- Multi-hop and transparent sessions
- Multi-tenancy via scopes
Semperis
On requestNo published plan breakdown. See the Semperis review.
Which should you pick?
Choose HashiCorp Boundary if
- You need identity-based access.
- You want to start without paying.
- You work on Linux, macOS, Windows, Web.
- You also want just-in-time credentials.
Choose Semperis if
- You need active directory forest recovery.
- You also want malware-free restore.
Questions people ask
- Is HashiCorp Boundary or Semperis better?
- Neither clearly leads. HashiCorp Boundary starts at Free and Semperis at On request, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
- Which is cheaper, HashiCorp Boundary or Semperis?
- HashiCorp Boundary has a free tier; the other does not. Paid plans start at Free for HashiCorp Boundary and On request for Semperis.
- Does HashiCorp Boundary or Semperis run on more platforms?
- HashiCorp Boundary runs on Linux, macOS, Windows, Web. Semperis runs on Web.
- Can I use HashiCorp Boundary for free?
- Yes. HashiCorp Boundary has a free tier, so you can try it without paying. Semperis starts at On request.
- What is HashiCorp Boundary best used for?
- HashiCorp Boundary is most often used for a platform team replacing shared ssh keys and a bastion host so that leavers lose access the moment they are removed from the identity provider, granting contractors time-boxed database access without ever issuing them a credential they could keep, an estate where autoscaling replaces hosts continuously and a static access list is always out of date, producing session recordings as evidence for an audit that requires proof of who touched production and what they ran. Of those, a platform team replacing shared ssh keys and a bastion host so that leavers lose access the moment they are removed from the identity provider and granting contractors time-boxed database access without ever issuing them a credential they could keep are not what Semperis is typically brought in for.
- What can HashiCorp Boundary do that Semperis cannot?
- HashiCorp Boundary covers Identity-based access, Just-in-time credentials, Dynamic host catalogues, Session recording. Semperis covers Active Directory Forest Recovery, Malware-free restore, Replication-stream monitoring, Automated rollback.
Answered from the vendors’ own pages
HashiCorp Boundary: Is Boundary open source?
The community edition is, under MPL 2.0. Boundary Enterprise is commercial and is now sold through IBM Passport Advantage.
Semperis: Does this replace my backups?
No. It replaces the Active Directory recovery procedure specifically. You still need backups for everything else, and the point of Semperis is that a generic system-state backup of a domain controller is a poor way to recover a forest because it restores the operating system along with whatever compromised it.
HashiCorp Boundary: Does it replace a VPN?
For infrastructure access, largely yes. It grants a session to a specific target rather than putting the user on a network, but it does not cover browser-based internal applications.
Semperis: Is it useful if we are cloud-only on Entra ID?
Partly. Directory Services Protector covers Entra ID and Okta for change tracking and posture, but the forest recovery product, which is the strongest reason to buy, applies to on-premises Active Directory. A genuinely cloud-only organisation should weigh it against Microsoft's own tooling.
HashiCorp Boundary: What does Boundary Enterprise cost?
HashiCorp does not publish Boundary pricing. It is quoted, and since the IBM acquisition it is transacted on IBM licensing paper.
Semperis: Are Purple Knight and Forest Druid really free?
Yes, both are free downloads with no licence requirement, and they are widely used by organisations that are not Semperis customers. They are also, transparently, the top of the sales funnel.
HashiCorp Boundary: Do I need Vault to use it?
No, but the just-in-time credential brokering that makes Boundary worthwhile depends on Vault or an equivalent secrets store.
Semperis: How long does forest recovery actually take?
The honest answer is whatever your rehearsal took. The vendor's case is hours instead of days, and automation genuinely removes most manual steps, but the number that matters for your board is the one from a test in your own environment.
Semperis: Does it require agents on domain controllers?
It collects directory changes from the AD replication stream, which is what lets it see changes that bypass the security log. Deployment details vary by product and version, so confirm the exact architecture against your domain controller change-control rules.
Related pages
More on HashiCorp Boundary
Other head to heads
- HashiCorp Boundary vs BeyondTrust
- HashiCorp Boundary vs Teleport
- HashiCorp Boundary vs Delinea
- HashiCorp Boundary vs Infisical
- HashiCorp Boundary vs 1Password
- HashiCorp Boundary vs LastPass
- HashiCorp Boundary vs authentik
- HashiCorp Boundary vs Logto
- HashiCorp Boundary vs Ory
- HashiCorp Boundary vs Saviynt
- HashiCorp Boundary vs Beyond Identity
- HashiCorp Boundary vs One Identity
- HashiCorp Boundary vs Keygen
- HashiCorp Boundary vs KnowBe4
- HashiCorp Boundary vs Legit Security
- HashiCorp Boundary vs LogRhythm SIEM
- HashiCorp Boundary vs Metasploit
- HashiCorp Boundary vs MetricStream
- HashiCorp Boundary vs Bitdefender Total Security
- HashiCorp Boundary vs Norton 360
- HashiCorp Boundary vs NICE Actimize
- HashiCorp Boundary vs Netwrix
- HashiCorp Boundary vs VMware Carbon Black
- HashiCorp Boundary vs Ping Identity
- HashiCorp Boundary vs Signicat
- HashiCorp Boundary vs CrowdStrike Falcon
- HashiCorp Boundary vs Authy
- HashiCorp Boundary vs Baffle
- HashiCorp Boundary vs Burp Suite
- HashiCorp Boundary vs Bitdefender VPN
- Semperis vs BeyondTrust
- Semperis vs Teleport
- Semperis vs Delinea
- Semperis vs Infisical
- Semperis vs 1Password
- Semperis vs LastPass
- Semperis vs authentik
- Semperis vs Logto
- Semperis vs Ory
- Semperis vs Saviynt
- Semperis vs Beyond Identity
- Semperis vs One Identity
- Semperis vs Keygen
- Semperis vs KnowBe4
- Semperis vs Legit Security
- Semperis vs LogRhythm SIEM
- Semperis vs Metasploit
- Semperis vs MetricStream
- Semperis vs Bitdefender Total Security
- Semperis vs Norton 360
- Semperis vs NICE Actimize
- Semperis vs Netwrix
- Semperis vs VMware Carbon Black
- Semperis vs Ping Identity
- Semperis vs Signicat
- Semperis vs CrowdStrike Falcon
- Semperis vs Authy
- Semperis vs Baffle
- Semperis vs Burp Suite
- Semperis vs Bitdefender VPN
