We're hard at work on a v2 that will be self-hostable as well as more powerful, flexible, and robust across the board so that it will be able to handle just about any configuration or secrets management scenario you can throw at it, from small teams to enterprise, while maintaining a simple, it-just-works approach.
In the meantime, our app and client libraries implement true end-to-end encryption that is open source and well-documented[1], meaning that despite our current product being cloud-hosted, we could not access your secrets even if we wanted to.
So take your time, and slowly move things to it, but vault is almost certainly worth your time and energy.
Plus combined with nomad and consul and the rest of the hashi stack it's pretty easy, and hard to get wrong.