Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Confidant is an open-source service designed for secret management, enabling secure and user-friendly storage and retrieval of sensitive information, developed by the team at Lyft. It addresses the challenge of authentication by leveraging AWS KMS and IAM, which enables IAM roles to create secure tokens that Confidant can validate. Additionally, Confidant oversees KMS grants for your IAM roles, facilitating the generation of tokens for service-to-service authentication and enabling encrypted communication between services. Secrets are stored in an append-only format within DynamoDB, with each revision of a secret linked to a distinct KMS data key, utilizing Fernet symmetric authenticated encryption for security. Furthermore, Confidant features a web interface built with AngularJS, allowing users to efficiently manage their secrets, associate them with services, and track the history of modifications. This comprehensive tool not only enhances security but also simplifies the management of sensitive data across various applications.
Description
APIs serve as the backbone for all your applications and services, but the secrets associated with them are often inadequately managed. These sensitive credentials are infrequently rotated, and in some cases, they may never be updated at all. The alarming frequency with which API keys, tokens, and even public key infrastructure (PKI) information are compromised is concerning. Therefore, having transparent insights and straightforward management of the machines accessing your APIs is essential. Many organizations struggle to maintain awareness of which machines are utilizing API secrets, and as the landscape of automation shifts the risk from human interactions to machines, understanding the identities of these machines along with the secrets they handle has become increasingly critical. Corsha provides a solution by preventing API breaches that exploit stolen or compromised credentials, enabling businesses to safeguard their data and applications that rely on machine-to-machine or service-to-service API interactions effectively. This proactive approach ensures not only security but also builds trust in the automated processes that modern enterprises depend on.
API Access
Has API
Yes
API Access
Has API
Yes
Integrations
AWS Amplify
Yes
Amazon DynamoDB
Yes
Amazon Web Services (AWS)
Yes
IAM Cloud
Yes
Integrations
AWS Amplify
No
Amazon DynamoDB
No
Amazon Web Services (AWS)
No
IAM Cloud
No
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
No
Webinars
No
Live Training (Online)
Yes
In Person
No
Vendor Details
Company Name
Confidant
Founded
2014
Website
lyft.github.io/confidant/
Vendor Details
Company Name
Corsha
Founded
2018
Country
United States
Website
corsha.com
Product Features
Privileged Access Management
Application Access Control
No
Behavioral Analytics
No
Credential Management
No
Endpoint Management
No
For MSPs
No
Granular Access Controls
No
Least Privilege
No
Multifactor Authentication
No
Password Management
No
Policy Management
No
Remote Access Management
No
Threat Intelligence
No
User Activity Monitoring
No
Product Features
API Management
API Design
No
API Lifecycle Management
No
Access Control
No
Analytics
No
Dashboard
No
Developer Portal
No
Testing Management
No
Threat Protection
No
Traffic Control
No
Version Control
No
Identity Management
Access Certification
No
Compliance Management
No
Multifactor Authentication
No
Password Management
No
Privileged Account Management
No
Self-Service Access Request
No
Single Sign On
No
User Activity Monitoring
No
User Provisioning
No