Start free. Pay when your team does.
Every plan is end-to-end encrypted. Paying moves the limits, never the security model.
Free
$0
For a small team keeping their keys out of .env files.
Start free trial- Up to 3 members, free forever
- 1 project · 10 secrets
- End-to-end encryption & CLI
- 7 days of audit history
Basic
Most teams$6/ user / month
For a small team that needs to review who reads what.
Start free trial- Up to 25 members · 3 teams
- 10 projects · 200 secrets each
- Access requests & device approvals
- Leak detection & webhooks
- 90 days of audit history
Professional
$15/ user / month
For an organisation that has to prove what happened.
Start free trial- Unlimited members · everything unlimited
- Single sign-on (OIDC & SAML)
- Break-glass & dynamic secrets
- Compliance reports & WORM audit
- 365 days of audit history
Every new organisation starts with 14 days of Professional, free and with no card. When it ends you move to Free — nothing is deleted and nobody loses access. Prices in USD, billed monthly. Paid plans charge per member of your organisation, including you. Service accounts, CLI tokens and CI identities are never charged as members. Cancel whenever you like.
Every limit, in full.
| Free | Basic | Professional | |
|---|---|---|---|
| Limits | |||
| Price per member | — | $6 / member | $15 / member |
| Projects | 1 | 10 | Unlimited |
| Secrets per project | 10 | 200 | Unlimited |
| Environments per project | 1 | 5 | Unlimited |
| Members | Up to 3 members | Up to 25 members | Unlimited |
| Teams | — | 3 | Unlimited |
| User groups | — | 5 | Unlimited |
| Service accounts | 1 | 5 | Unlimited |
| Certificates | 3 | 25 | Unlimited |
| Credentials | 5 | 50 | Unlimited |
| Audit history | 7 days | 90 days | 365 days |
| Features | |||
| Webhooks | — | 3 endpoints | Unlimited |
| Dynamic secrets | — | 1 engine | Unlimited |
| Kubernetes clusters | — | 1 cluster | Unlimited |
| OIDC trust policies | — | 5 policies | Unlimited |
| Device approvals | Not included | Included | Included |
| Time-based access | Not included | Included | Included |
| Access request workflow | Not included | Included | Included |
| Leak detection | Not included | Included | Included |
| GitHub integration | Not included | Included | Included |
| Break-glass access | Not included | Not included | Included |
| Single sign-on | Not included | Not included | Included |
| Compliance reports | Not included | Not included | Included |
| WORM audit log | Not included | Not included | Included |
| Organisation layer | Not included | Not included | Included |
Still deciding?
The FAQ covers what we can and cannot see, what happens if you forget your password, and how sharing works without anyone swapping a password. If it's not there, ask us.