ov scan is always free — no account, no email, no catch.
The vault starts free. Upgrade when you're ready to ship.
For developers exploring OpaqueVault. Interceptor included — zero-knowledge from your first secret.
For individual developers who live in Claude Code, Cursor, or any MCP-native AI tool.
ov scan — no account required.Scan any repo for leaked secrets right now. No signup. No telemetry. Runs entirely on your machine. AWS keys, Stripe tokens, private keys, connection strings — found and reported before they become a breach.
| Free | Solo | |
|---|---|---|
| Vault | ||
| Secrets | 10 | Unlimited |
| Apps | 1 | Unlimited |
| API keys | 1 | Multiple |
| AI Security | ||
| MCP context interceptor | ✓ | ✓ |
| All 8 MCP tools | — | ✓ |
| ov scan (repo scanner) | ✓ always free | ✓ always free |
| Audit + Compliance | ||
| Audit log retention | — | 90 days |
| Interceptor events in audit log | ✓ | ✓ |
| Crypto | ||
| AES-256-GCM envelope encryption | ✓ | ✓ |
| ML-KEM-768 + X25519 hybrid PQC | ✓ | ✓ |
| Zero-knowledge (server never decrypts) | ✓ | ✓ |
| Support | ||
| Community (GitHub) | ✓ | ✓ |
| $0 | $5/mo | |
| Start free | Start Solo | |
Yes. The MCP context interceptor is included on every plan including Free. It's a core safety guarantee, not a premium feature. Zero-knowledge means nothing if you can accidentally bypass it by pasting a secret into chat.
ov scan send my code anywhere?
No. ov scan runs entirely on your machine. No network calls, no telemetry,
no account required. It's a local binary scanning local files. We never see your code or your secrets.
Never. The server stores only ciphertext. Your Key Encryption Key (KEK) is derived from your master password using Argon2id and never leaves your machine. There is no decrypt endpoint, no key escrow, and no way for OpaqueVault staff to read your secrets even if subpoenaed.
You'll be prompted to upgrade when you try to create your 11th secret. Existing secrets are never deleted or locked — you can always read, update, and delete them. Only creation of new secrets is gated.
Any MCP-compatible client: Claude Code, Cursor, Windsurf, and anything else that speaks
the Model Context Protocol. ov mcp serve is the bridge — one binary, any client.
No credit card required. No time limit on the free tier.
ov scan is free forever.