Pricing
Start free, then upgrade when the Stripe proof drill is green.
SecretSeal plans are built around the real product: team vault, Secure Send / Receive, Shared2FA, and MCP/CLI access for trusted AI workflows.
Team vault
Passwords, API keys, recovery codes, secure notes, and client credentials in encrypted records.
Secure Send / Receive
Move one-time secrets and client submissions out of email and chat threads.
Shared2FA
Keep operational authenticator access from depending on one person's phone.
MCP and CLI
Give Codex, Claude Code, and local automation scoped metadata-first access.
Starter
Try one credential-handoff workspace for team vault records, secure exchange, Shared2FA, and audit history.
No Stripe checkout required.
Team
RecommendedFor teams that need one place for client credentials, authenticator continuity, and AI-safe MCP/CLI access.
Paid checkout starts only after Stripe env proof is green.
Business
For teams that need stronger controls around approvals, client systems, compliance evidence, and operator handoff.
Use readiness checks before selling this plan.
Paid rollout path
Sell paid plans only after proof is green.
The product can start free today, but Team and Business checkout stay behind readiness until Stripe configuration and real reconciliation proof are present.
Start free workspace
Use Starter to prove vault records, Secure Send / Receive, Shared2FA, audit events, and MCP/CLI metadata access without Stripe checkout.
Run Stripe proof drill
Team and Business buyers move through checkout, portal, webhook, customer, subscription, and proof checks before paid plans are sold.
Record Stripe proof
Paid launch turns green only after real production Stripe checkout, customer portal, webhook event, live workspace reconciliation, and verification timestamp are recorded.
Run launch proof pack
Before selling the full SecretSeal promise, confirm paid billing, native Authenticator parity, and live MCP/CLI agent proof gates in one operator handoff.
SaaS launch gates
The plans define the buyer promise. Paid checkout should remain gated until Stripe configuration, webhook reconciliation, and workspace subscription state are proven in production.
Non-secret Stripe proof handles
Current paid billing proof snapshot
Run a real production Stripe checkout, then record a non-secret cs_live_... checkout session handle.
Paid checkout
Checkout, portal, and webhook routes are built, but production Stripe environment variables must be verified before selling paid plans.
Agent access
MCP and CLI support metadata discovery, safe import planning, approval workflows, and non-destructive ops plans; live agent launch proof still needs real configuration.
Mobile approval
PWA and native approval contracts exist; real-device push, biometric approval, and app packaging remain release gates.
Security boundary
Default agent and readiness surfaces do not return actual API keys, plaintext payloads, TOTP seeds, generated codes, or encrypted payloads.
Workspace management
Invite members, separate client and team scopes, and keep records attached to the right workspace.
Authenticator-grade direction
Shared2FA is built around fast review, local unlock, approval queues, and native biometric approval targets.
Zero-knowledge posture
Vault payloads, recovery codes, TOTP seeds, and private notes stay encrypted while metadata drives operations.
Ready to test the workspace?
Start free now. Move Team and Business buyers through the Stripe proof drill once Stripe production configuration is verified.