The CyberArk platform, delivered module by module
CyberArk isn't one product — it's a platform of modules, each solving a different part of privileged access. This page walks through what the Vault and Privilege Cloud, Privileged Session Manager, Endpoint Privilege Manager, and Conjur secrets each do, and which ones your environment needs. The portfolio now sits under Palo Alto Networks, though the components are unchanged. Chasing a specific error message? See error fixes.
Looking for a full rollout rather than a single module? See our CyberArk implementation & delivery.
Which CyberArk modules you need depends on your risk
Most CyberArk conversations start with "we bought CyberArk" and stall on "…now what do we turn on?" The platform spans credential vaulting, session control, endpoint privilege, and application secrets — and buying all of it at once is the fastest way to a deployment that never finishes.
We deliver CyberArk one module at a time, sequenced by where your privileged risk actually sits. Below is what each module does and how we roll it out. If you want the end-to-end engagement — scoping, licensing, and a managed handover — that's covered on our CyberArk implementation page.
The CyberArk modules we deploy
Each one deployed to a hardened baseline and integrated with your directory, SIEM, and ITSM — not left on installer defaults.
CyberArk Privilege Cloud
The SaaS-hosted version of the CyberArk vault. CyberArk runs the vault infrastructure and you consume it as a service, so there's no hardware to stand up and rollout is materially faster than a self-hosted build. We provision the tenant, design safe structure and rotation policy, integrate it with your directory, and onboard privileged accounts in controlled waves.
CyberArk EPM — Endpoint Privilege Manager
EPM removes standing local-admin rights from endpoints and servers and grants elevation only for approved actions. It closes the gap most PAM programs leave open — users still running as admin on their own machine — and contains ransomware by blocking unapproved executables from running with privilege. We deploy it audit-first, so you see what would break before anything is enforced.
CyberArk PSM — Privileged Session Manager
PSM brokers privileged sessions so the admin never holds the real credential. The connection is proxied, isolated from the endpoint, and fully recorded — giving you an audit trail and a kill switch for every privileged session. It's also how secure remote and third-party access is done properly, without VPNs and shared passwords.
CyberArk Conjur — secrets management
Conjur is the secrets engine inside CyberArk Secrets Manager. It pulls application, DevOps, and machine-to-machine credentials out of code, config files, and environment variables, and issues them at runtime with rotation and policy. If developers are hard-coding API keys or keeping secrets in a repo, this is the module that fixes it.
CyberArk Vault (self-hosted)
The self-hosted core — Vault, CPM, and PVWA — for teams that need to own the infrastructure for compliance, latency, or sovereignty reasons. We design safe structure and ownership up front, set rotation policy before a single account is onboarded, and harden the build to the controls you report against rather than to defaults.
The same disciplined path for every module
New module on a clean environment, or an addition to a deployment you already run.
Scope
We confirm which module fits the risk, and the integration points it needs.
Deploy & harden
We stand it up to a secure baseline, not installer defaults.
Integrate
We wire it into your directory, SIEM, ITSM, and the apps that depend on it.
Onboard & hand over
We onboard accounts in waves and hand you runbooks — or run it for you.
Common questions about the CyberArk modules
What is CyberArk EPM?
What's the difference between the CyberArk Vault and Privilege Cloud?
What does CyberArk PSM do?
Is CyberArk Conjur the same as Secrets Manager?
Do we need every CyberArk module?
Can you add a CyberArk module to an existing deployment?
Who actually delivers the CyberArk modules?
Not sure which CyberArk modules you need?
Tell us where your privileged risk sits and what you already own. We'll map it to the right modules — Privilege Cloud, EPM, PSM, or Conjur — and put certified engineers on the rollout.


