Story
Garmin Standardizes Developer Security on HashiCorp
Garmin, a consumer discretionary organization in the United States, uses Vault from HashiCorp to support secure delivery for developers and AppSec.
Value results
| Category | Value result |
|---|---|
| Risk and compliance | Developer security can be reviewed without waiting on a personal export |
| Risk and compliance | Named workflow replaces ad hoc routing for developer security |
| Capability | Secure delivery stays visible to adjacent teams through Vault |
Story
Consumer Discretionary work at Garmin spans more than one site, even when headquarters sits in the United States. Developer security was splitting across regional habits. Developers and AppSec asked for a shared way to run secure delivery without freezing local judgment.
HashiCorp (Vault) is what they standardized on. HashiCorp (an IBM company) provides infrastructure automation software, including Terraform and Vault, for cloud provisioning and secrets. Garmin uses it as the system of record for developer security, with developers and AppSec as the primary operators and other groups coming in through the same queue.
Leaders get a picture they can actually walk. Teams get fewer mystery statuses. The story is about operating change, not an unpublished percentage.