Cybersecurity · head to head
Trivy vs Vault

Trivy
Cybersecurity
Open-source vulnerability and misconfiguration scanner
- From
- Free
- Rated
- -
The short version
- Each has a real cost: Trivy reports what public advisory databases know, so coverage varies by ecosystem and unfixed CVEs create noise; Vault vault 1.15.0 and later is licensed under the Business Source License 1.1, not an OSI open source licence, with IBM Corporation as licensor
- They diverge on capability: Trivy covers Multi-target scanning, Vault covers Secrets management.
- Prices and features above were last checked on 30 August 2026.
Where they differ
Only the attributes on which Trivy and Vault actually diverge.
Identical on both: starting price (Free), free tier (Yes), user rating (Not yet rated).
What each one covers
Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.
Only in Trivy
- Multi-target scanning
- Vulnerability detection
- Misconfiguration checks
- Secret detection
Only in Vault
- Secrets management
- Encryption
- Authentication
- Authorization
- Audit logging
- API access
- High availability
- Replication
What people use each for
The jobs each tool is most often brought in to do.
Trivy
- Failing a pull request when a container image introduces a known CVEnot Vault
- Scanning Terraform and Kubernetes manifests for misconfiguration before applynot Vault
- Catching committed secrets as part of an existing CI stepnot Vault
Vault
- Centrally storing and rotating secrets, API keys and database credentialsnot Trivy
- Issuing short-lived dynamic credentials to applications instead of static passwordsnot Trivy
- Encryption as a service and PKI certificate issuancenot Trivy
Where each one falls short
Documented limitations, not opinions. Every one is a constraint you would hit in normal use.
Trivy
- Reports what public advisory databases know, so coverage varies by ecosystem and unfixed CVEs create noise
- No built-in triage or exception workflow, so suppressing accepted risk is managed in config files
- Findings are point-in-time from CI, with no continuous runtime monitoring unless you add the commercial platform
Vault
- Vault 1.15.0 and later is licensed under the Business Source License 1.1, not an OSI open source licence, with IBM Corporation as licensor
- The Additional Use Grant forbids offering Vault to third parties on a hosted or embedded basis in a paid product that competes with IBM's paid versions of Vault
- Each version only converts to MPL 2.0 four years after that version is published, and the Change Date is tracked per version
- Replication, HSM support, namespaces, performance standby nodes, FIPS builds, control group authorisation, multi-factor authentication, secrets sync and lease count quotas all require a Vault Enterprise licence
- A Vault Enterprise licence must be applied to the cluster before any Enterprise feature can be used
Pricing, plan by plan
Trivy
Free- TrivyFree
- Full scanner
- Unlimited scans
- Community support
Vault
Free- Open SourceFree
- Secrets management
- Encryption as a service
- Identity management
- EnterpriseFree
- Advanced features
- Premium support
- Dedicated updates
Which should you pick?
Choose Trivy if
- You need multi-target scanning.
- You want to start without paying.
- You work on Linux, macOS, Windows, Docker, Kubernetes.
- You also want vulnerability detection.
Choose Vault if
- You need secrets management.
- You want to start without paying.
- You work on Linux, Windows, Mac, Cloud.
- You also want encryption.
Questions people ask
- Is Trivy or Vault better?
- Neither clearly leads. Trivy starts at Free and Vault at Free, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
- Which is cheaper, Trivy or Vault?
- Trivy starts at Free and Vault at Free.
- Does Trivy or Vault run on more platforms?
- Trivy runs on Linux, macOS, Windows, Docker, Kubernetes. Vault runs on Linux, Windows, Mac, Cloud.
- Can I use Trivy for free?
- Both have a free tier, so you can try either at no cost before committing.
- What is Trivy best used for?
- Trivy is most often used for failing a pull request when a container image introduces a known cve, scanning terraform and kubernetes manifests for misconfiguration before apply, catching committed secrets as part of an existing ci step. Of those, failing a pull request when a container image introduces a known cve and scanning terraform and kubernetes manifests for misconfiguration before apply are not what Vault is typically brought in for.
- What can Trivy do that Vault cannot?
- Trivy covers Multi-target scanning, Vulnerability detection, Misconfiguration checks, Secret detection. Vault covers Secrets management, Encryption, Authentication, Authorization.
Answered from the vendors’ own pages
Trivy: Is Trivy free?
Yes, open source from Aqua Security with no licence fee. Aqua sells a commercial platform around it.
Vault: Is HashiCorp Vault free to use?
Yes, Vault is available as a free, open-source project. The community version includes secrets management, certificate generation and rotation, encryption services, and credential management. Vault Enterprise is a commercial offering with additional features.
SourceTrivy: What can Trivy scan?
Container images, filesystems, Git repositories, Kubernetes clusters and infrastructure-as-code, for vulnerabilities, misconfigurations, secrets and licences.
Vault: What are the differences between open-source Vault and Vault Enterprise?
Open-source Vault is free and self-hosted. Vault Enterprise includes additional features and commercial support. HashiCorp also offers Vault Dedicated on the HashiCorp Cloud Platform as a fully managed cloud option.
SourceTrivy: Does Trivy need a server?
No. It is a single binary, which is a large part of why it became a default in CI.
Vault: Can I try HashiCorp Cloud Platform Vault without payment?
Yes, HashiCorp offers a free trial option for HCP Vault Dedicated. New users also receive a $500 credit to use across HashiCorp Cloud Platform services.
SourceVault: What does Vault manage and protect?
Vault provides identity-based secrets management for users, machines, services, and AI agents. It automates authentication and authorization for access to secrets, passwords, certificates, encryption keys, and other sensitive data across your infrastructure.
SourceRelated pages
Other head to heads
- Trivy vs Grype
- Trivy vs Snyk
- Trivy vs Chainguard
- Trivy vs Semgrep
- Trivy vs Bitwarden
- Trivy vs Infisical
- Trivy vs Authelia
- Trivy vs Ory Kratos
- Trivy vs HashiCorp Vault
- Trivy vs Arnica
- Trivy vs OWASP ZAP
- Trivy vs Proton Mail
- Trivy vs Veriff
- Trivy vs Brave Browser
- Trivy vs March Networks
- Trivy vs Salient CompleteView
- Trivy vs Sumsub
- Trivy vs Syft
- Trivy vs AWS (Amazon Web Services)
- Trivy vs DigitalOcean
- Trivy vs Grafana Cloud
- Trivy vs Neon
- Trivy vs Crossplane
- Trivy vs Microsoft Azure
- Trivy vs Podman
- Trivy vs Hetzner Cloud
- Trivy vs Linode
- Trivy vs Vultr
- Trivy vs Akamai
- Trivy vs Alibaba Cloud
- Trivy vs CapRover
- Trivy vs Chef
- Trivy vs Buildah
- Vault vs Grype
- Vault vs Snyk
- Vault vs Chainguard
- Vault vs Semgrep
- Vault vs Bitwarden
- Vault vs Infisical
- Vault vs Authelia
- Vault vs Ory Kratos
- Vault vs HashiCorp Vault
- Vault vs Arnica
- Vault vs OWASP ZAP
- Vault vs Proton Mail
- Vault vs Veriff
- Vault vs Brave Browser
- Vault vs March Networks
- Vault vs Salient CompleteView
- Vault vs Sumsub
- Vault vs Syft
- Vault vs AWS (Amazon Web Services)
- Vault vs DigitalOcean
- Vault vs Grafana Cloud
- Vault vs Neon
- Vault vs Crossplane
- Vault vs Microsoft Azure
- Vault vs Podman
- Vault vs Hetzner Cloud
- Vault vs Linode
- Vault vs Vultr
- Vault vs Akamai
- Vault vs Alibaba Cloud
- Vault vs CapRover
- Vault vs Chef
- Vault vs Buildah

