Free plan available

Secrets management your team, your CI, and your agents can trust.

Versioned, envelope-encrypted secrets across workspaces, projects, and environments. A CLI that injects them straight into your process, and an MCP connector that gives agents the same scoped, audited access — never a plaintext file on disk. Approvals, audit logs, and rotation built in, not bolted on.

$ vaultic login
✓ Signed in as you@company.com

$ vaultic secrets set STRIPE_KEY sk_live_•••
✓ Stored in production (v4)

$ vaultic run -- node server.js
✓ Injected 12 secrets from production

$ 

Everything a secrets store should do

Workspaces → projects → environments, with versioned, encrypted values at every level and a matrix view to see what's set where.

Simple, per-seat pricing

Free to start. €6 per seat a month (excl. VAT) once your team needs more — machine identities are always unlimited, on every plan.

Free

€0/mo

Core secrets, environments, CLI, API, MCP agent access, and rotation reminders.

  • Owned workspaces2
  • Projects / workspace3
  • Members / workspace5
  • Base environments / project3
  • Audit log retention30 days
  • Service tokensUnlimited
  • —Provider-assisted rotation execution
  • —Change requests & approvals
  • —Webhooks & syncs
  • —Trusted IPs
  • —Secret share links
  • —SSO
Start free

Enterprise

Contact us

Everything in Team, deployed the way your compliance team requires.

  • DeploymentSelf-hosted or our cloud
  • InfrastructureYours, or fully managed by us
  • SupportDedicated, contract-backed
  • Everything in Team, unlimited
  • Self-hosted on your own infrastructure
  • Or fully managed, hosted in our cloud
  • Custom contract & support terms
Contact us

Prices shown are excl. VAT (HT) — VAT or local sales tax is calculated automatically at checkout based on your billing location. Billed monthly through Stripe — manage seats or cancel anytime from workspace settings. Seat count follows your member count automatically. Full plan comparison →

MCP

Give your agents secrets, not your .env file

Vaultic hosts an MCP connector so Claude — or any other MCP client — connects over HTTPS with OAuth and reads/writes secrets through the same scoped, audited path as your CLI and web UI. No JSON config, no token pasted into a dotfile, no agent ever opening a local secrets file.

  • Add it from Settings → Connectors with a URL — the same way you'd add any remote MCP connector.
  • Scoped service tokens — read-only by default, pinned to one project and one environment.
  • Every agent call is tagged source: mcp in the audit log — distinct from cli, ui, and api activity.
  • Reveals are audited separately from masked listings — an agent that lists secrets isn't the same log line as one that reads a value.
Claude → Settings → Connectors
1
Add custom connector

Paste your workspace's Vaultic connector URL.

2
Approve in Vaultic

Pick a workspace, project, environment, and read-only or write.

3
Scoped token, minted for you

Vaultic mints it behind the OAuth exchange — Claude never sees it, and it's never written to a file.

4
Every call, audited

Tagged source: mcp in the audit log, same as the CLI and web UI.

Encrypted at every layer, not behind a single shared key

Every secret you store goes through three layers of encryption before it ever touches disk — each layer scoped narrower than the last.

Master key
Threshold-split across operator-held shares, or wrapped by AWS KMS. Plaintext-on-disk is refused outright in production.
Workspace key
One per workspace. A breach of one workspace's key never exposes another workspace's secrets.
Secret key (AES-256-GCM)
One per secret, fresh random IV on every write. Decrypting one value never decrypts the rest.

Three separate keys, three separate jobs — compromising one layer never hands over the others. Change proposals on locked environments get their own fresh key before an approver ever sees the value.

A CLI that fits your existing workflow

Init a project, and secrets flow into your process with one command — locally and in CI.

$ vaultic init
✓ Linked ./my-app to acme/api/development

$ vaultic run --watch -- npm run dev
✓ Watching for secret changes, live-reloading

$ vaultic export --check
✓ .env matches the server — safe to deploy

$ 

Start free. Upgrade when your team needs it.

No credit card for Free. Team is €6/seat/mo excl. VAT, billed through Stripe.