Pricing

Start free, then upgrade when the Stripe proof drill is green.

SecretSeal plans are built around the real product: team vault, Secure Send / Receive, Shared2FA, and MCP/CLI access for trusted AI workflows.

Team vault

Passwords, API keys, recovery codes, secure notes, and client credentials in encrypted records.

Secure Send / Receive

Move one-time secrets and client submissions out of email and chat threads.

Shared2FA

Keep operational authenticator access from depending on one person's phone.

MCP and CLI

Give Codex, Claude Code, and local automation scoped metadata-first access.

Starter

Available now

Try one credential-handoff workspace for team vault records, secure exchange, Shared2FA, and audit history.

$0trial workspace
Start trial

No Stripe checkout required.

Personal and team workspaces
Secure Send / Receive links
Shared2FA records
Passkey sign-in
Core audit events

Team

Recommended
Checkout gated by Stripe proof

For teams that need one place for client credentials, authenticator continuity, and AI-safe MCP/CLI access.

$19per user / month
Review Team launch gate

Paid checkout starts only after Stripe env proof is green.

Everything in Starter
Workspace roles and invitations
Vault collections and rotation tracking
Scoped API keys for CLI and MCP
Shared2FA approval workflow
Workspace audit log

Business

Checkout gated by Stripe proof

For teams that need stronger controls around approvals, client systems, compliance evidence, and operator handoff.

$49per user / month
Review Business launch gate

Use readiness checks before selling this plan.

Everything in Team
Approval policies for sensitive reveals
Advanced API-key monitoring
Emergency access process
Priority onboarding
Security review support

Paid rollout path

Sell paid plans only after proof is green.

The product can start free today, but Team and Business checkout stay behind readiness until Stripe configuration and real reconciliation proof are present.

1

Start free workspace

Use Starter to prove vault records, Secure Send / Receive, Shared2FA, audit events, and MCP/CLI metadata access without Stripe checkout.

2

Run Stripe proof drill

Team and Business buyers move through checkout, portal, webhook, customer, subscription, and proof checks before paid plans are sold.

3

Record Stripe proof

Paid launch turns green only after real production Stripe checkout, customer portal, webhook event, live workspace reconciliation, and verification timestamp are recorded.

4

Run launch proof pack

Before selling the full SecretSeal promise, confirm paid billing, native Authenticator parity, and live MCP/CLI agent proof gates in one operator handoff.

SaaS launch gates

The plans define the buyer promise. Paid checkout should remain gated until Stripe configuration, webhook reconciliation, and workspace subscription state are proven in production.

Non-secret Stripe proof handles

STRIPE_VERIFIED_CHECKOUT_SESSION_ID=cs_live_...
STRIPE_VERIFIED_PORTAL_SESSION_ID=bps_...
STRIPE_VERIFIED_WEBHOOK_EVENT_ID=evt_...
STRIPE_VERIFIED_RECONCILED_WORKSPACE_ID=wrk_<live_workspace_id>
STRIPE_VERIFIED_AT=<iso_timestamp>

Current paid billing proof snapshot

paid-saas-billing1/5 ready

Run a real production Stripe checkout, then record a non-secret cs_live_... checkout session handle.

STRIPE_VERIFIED_CHECKOUT_SESSION_IDSTRIPE_VERIFIED_PORTAL_SESSION_IDSTRIPE_VERIFIED_WEBHOOK_EVENT_IDSTRIPE_VERIFIED_RECONCILED_WORKSPACE_IDSTRIPE_VERIFIED_AT
Record only non-secret Stripe proof handles after real production checkout, portal, webhook, live workspace reconciliation, and the final timestamp are verified.
Never paste Stripe secret keys, webhook secrets, price IDs, customer IDs, subscription IDs, or raw billing payloads.
Keep Team and Business checkout behind readiness until every proof handle is current.
External config required

Paid checkout

Checkout, portal, and webhook routes are built, but production Stripe environment variables must be verified before selling paid plans.

Needs live proof

Agent access

MCP and CLI support metadata discovery, safe import planning, approval workflows, and non-destructive ops plans; live agent launch proof still needs real configuration.

Partial

Mobile approval

PWA and native approval contracts exist; real-device push, biometric approval, and app packaging remain release gates.

Enforced

Security boundary

Default agent and readiness surfaces do not return actual API keys, plaintext payloads, TOTP seeds, generated codes, or encrypted payloads.

Workspace management

Invite members, separate client and team scopes, and keep records attached to the right workspace.

Authenticator-grade direction

Shared2FA is built around fast review, local unlock, approval queues, and native biometric approval targets.

Zero-knowledge posture

Vault payloads, recovery codes, TOTP seeds, and private notes stay encrypted while metadata drives operations.

Ready to test the workspace?

Start free now. Move Team and Business buyers through the Stripe proof drill once Stripe production configuration is verified.

SecretSeal

Team vault, Secure Send / Receive, Shared2FA, and AI-safe MCP/CLI controls.