How It Works

From Deployment to Protection in Minutes

VaultGuard360 deploys as an Azure Managed Application directly from Azure Marketplace. It runs entirely within your Azure tenant, using a managed identity to securely scan your Key Vaults.

1

Deploy from Azure Marketplace

~5 minutes

Search for "VaultGuard360" in Azure Marketplace, click "Create" and select your subscription, choose your tier, configure basic settings, and deploy.

2

Grant Permissions

~5 minutes

VaultGuard360 uses a managed identity to access your Key Vaults. Grant "Key Vault Reader" permissions at the appropriate scope.

3

Configure Notifications

~10 minutes

Set up your notification email address and team routing. Configure webhook URLs for additional integrations.

4

Set Alert Thresholds

~2 minutes

Choose when to be notified (30, 14, 7 days before expiration). Professional/Enterprise can set custom thresholds.

5

You're Protected

Ongoing

VaultGuard360 scans daily and sends alerts automatically. View your dashboard or wait for email alerts.

Coverage

What Gets Scanned

Item TypeWhat We Monitor
SecretsName, expiration date, enabled status
CertificatesName, expiration date, enabled status
KeysName, expiration date, enabled status

Important: VaultGuard360 never reads or stores actual secret values. Only metadata required for expiration tracking.

Security

Your Data Stays Yours

Runs in Your Tenant

VaultGuard360 runs entirely in your Azure subscription as a Managed Application.

Managed Identity

Uses Azure Managed Identity with no stored credentials. We never have access to your secrets.

Azure Resource Manager

Scans via Azure Resource Manager APIs, reading only metadata — never secret values.

No External Transmission

Alert metadata is sent via your own Microsoft 365 email. No external data transmission.

Ready to Deploy?

Get started in minutes with our Azure Marketplace deployment. Your first scan runs automatically.