ov scan is always free — no account, no email, no catch.
The vault starts free. Upgrade when you're ready to ship.
For developers exploring OpaqueVault. Interceptor included — zero-knowledge from your first secret.
For individual developers who live in Claude Code, Cursor, or any MCP-native AI tool.
ov scan — no account required.Scan any repo for leaked secrets right now. No signup. No telemetry. Runs entirely on your machine. AWS keys, Stripe tokens, private keys, connection strings — found and reported before they become a breach.
| Free | Solo | |
|---|---|---|
| Vault | ||
| Secrets | 10 | Unlimited |
| Apps | 1 | Unlimited |
| API keys | 1 | Multiple |
| AI Security | ||
| MCP context interceptor | ✓ | ✓ |
| All 8 MCP tools | — | ✓ |
| ov scan (repo scanner) | ✓ always free | ✓ always free |
| Audit + Compliance | ||
| Audit log retention | — | 90 days |
| Interceptor events in audit log | ✓ | ✓ |
| Crypto | ||
| AES-256-GCM envelope encryption | ✓ | ✓ |
| ML-KEM-768 + X25519 hybrid PQC | ✓ | ✓ |
| Zero-knowledge (server never decrypts) | ✓ | ✓ |
| Support | ||
| Community (GitHub) | ✓ | ✓ |
| $0 | $5/mo | |
| Start free | Start Solo | |
Yes. The MCP context interceptor is included on every plan including Free. It's a core safety guarantee, not a premium feature. Zero-knowledge means nothing if you can accidentally bypass it by pasting a secret into chat. Read more about how the interceptor works.
ov scan send my code anywhere?
No. ov scan runs entirely on your machine. No network calls, no telemetry,
no account required. It's a local binary scanning local files. We never see your code or your secrets.
See ov scan reference.
Never. The server stores only ciphertext. Your Key Encryption Key (KEK) is derived from your master password using Argon2id and never leaves your machine. There is no decrypt endpoint, no key escrow, and no way for OpaqueVault staff to read your secrets even if subpoenaed. See the zero-knowledge guarantee.
You'll be prompted to upgrade when you try to create your 11th secret.
Existing secrets are never deleted or locked — you can always read, update, and delete them.
Only creation of new secrets is gated.
See the ov secret commands.
Any MCP-compatible client: Claude Code, Cursor, Windsurf, and anything else that speaks
the Model Context Protocol. ov mcp serve is the bridge — one binary, any client.
See setup guides for Claude Code and Cursor.
No credit card required. No time limit on the free tier.
ov scan is free forever.