Delinea

Primary category: secrets-management. Also listed in identity-access and non-human-identity.

One-liner — A privileged access management incumbent assembled from Thycotic and Centrify by TPG — the mid-market alternative to CyberArk, with credential vaulting (Secret Server) as its centre of gravity.

What it does — PAM in the classic sense. Secret Server (the Thycotic heritage) is the privileged-credential vault: discovery of privileged accounts, storage, rotation, and checkout with approval. Around it sit privileged session management and recording, endpoint privilege management (removing local admin rights while allowing specific elevated actions), and the identity-consolidation work inherited from Centrify. Increasingly marketed around machine and non-human identities — service accounts, workloads and now AI agents — which is why it also appears under non-human-identity.

Naming / provenance — read this before searching. Four names for one thing. Thycotic (Secret Server) and Centrify were separate PAM companies. TPG bought Thycotic from Insight Partners and Centrify from Thoma Bravo, merged them in April 2021 as ThycoticCentrify, and renamed the combination Delinea in February 2022. Any comparison content, analyst note or customer reference older than 2022 will use one of the legacy names for what is now the same vendor.

Ownership & viabilitype-owned by TPG Capital, with Thoma Bravo and PSP Investments holding minority stakes. Five-plus years into the hold on a merged asset — late in a normal PE cycle, so a sale, recapitalisation or IPO is a reasonable expectation. Financially sound; the risks are commercial. The specific thing to price in: merged-product estates under PE ownership reliably produce end-of-life decisions on the losing product line and renewal-price increases. Ask directly which components are strategic and which are in maintenance before committing.

Positioning & differentiators

  • Secret Server is genuinely good and genuinely established. It is the product most mid-market firms actually deploy, and it deploys faster than cyberark.
  • On-prem is first-class, not a legacy concession — relevant for firms that will not put a privileged-credential vault in a vendor cloud.
  • Positioned below cyberark, above keeper. More capable and more expensive than Keeper; less deep and less expensive than CyberArk. That middle slot is the whole proposition.
  • Merger integration is the standing question. Thycotic and Centrify overlapped substantially, and a buyer should establish which code base underlies what they are being sold.

Who should choose them / anti-fit — Fits a mid-size regulated firm that needs real privileged-credential control, session recording for audit, and endpoint privilege removal, without a CyberArk-scale programme. Privileged access is a standard SEC-examination and cyber-insurance topic, so this is a defensible baseline purchase for an alternative manager. Anti-fit: a firm with the largest and most complex privileged estates (cyberark); a cloud-native platform team wanting dynamic short-lived secrets (hashicorp-vault); a small shop that only needs a vault (keeper, 1password).

Known weaknesses / gotchas — Product-line overlap from the merger, and the associated end-of-life risk. PE renewal pricing. The Centrify-heritage identity components have had a less clear roadmap than the Thycotic-heritage vault. Delinea also disclosed a security incident affecting its cloud Secret Server tenants in April 2024, which took portals offline — old and remediated, but directly relevant history for a vendor holding privileged credentials, and worth raising in diligence.

Deployment & data handling — SaaS, on-prem and hybrid. For the SaaS path, key management, tenancy isolation and recovery are unverified and are the critical questions given what the product holds.

Integrations & partnerships — IdP/directory, ITSM, SIEM, DevOps and CI/CD secrets injection. MCP support unverified.

Compliance & FS tractionUnverified in specifics. Large regulated-industry base is presumed; no named FS references confirmed. Certifications not confirmed.

Commercial — Not public. Per-user / per-secret enterprise licensing; typically well below CyberArk.

Open questions

  • Which merged product lines are strategic and which are in maintenance mode.
  • Cloud key-management and tenancy-isolation model for Secret Server Cloud; post-2024-incident changes.
  • TPG hold period and exit expectations.
  • Certifications held (FedRAMP status).
  • Substance of the AI-agent / non-human-identity positioning versus renamed service-account management.

Sources

History

  • [2026-08-26] Page created via wiki-create + researched same day. Found by diffing the live SurveyMonkey instrument against the wiki.