Story
Marks and Spencer Standardizes Developer Security on HashiCorp
Marks and Spencer, a consumer discretionary organization in the United Kingdom, uses Vault from HashiCorp to support secure delivery for developers and AppSec.
Value results
| Category | Value result |
|---|---|
| Risk and compliance | Developers and AppSec work from the same Vault record for developer security |
| Risk and compliance | Developer security can be reviewed without waiting on a personal export |
| Capability | Secure delivery stays visible to adjacent teams through Vault |
Story
Marks and Spencer is based in the United Kingdom and runs consumer discretionary operations at a scale where developer security cannot live in side channels. Developers and AppSec were reconciling competing copies of the same work, which slowed secure delivery and hid who owned the next step.
The company runs secure delivery on HashiCorp, with Vault as the product developers and AppSec actually open. HashiCorp (an IBM company) provides infrastructure automation software, including Terraform and Vault, for cloud provisioning and secrets. For Marks and Spencer, that means developers and AppSec can open one workflow, see developer security, and let neighboring teams join without inventing a parallel stack.
Public materials confirm the companies and products. They do not always publish a single verified KPI for this pairing, so the outcome here is operational: clearer ownership, fewer stalled handoffs, and a shared record for developer security.