// pricing

Pay for capacity, never for trust

Every plan uses the same end-to-end encryption, so your secrets are unreadable to us at any tier. Upgrading buys more devices, bigger shares, and team features.

betaEverything is free while Pock is in beta. Billing isn't switched on yet.

These are launch prices. Sign up now and keep Pro free for 12 months after billing launches.

Free

Personal, forever

$0forever

  • Full end-to-end encrypted vault
  • Up to 3 devices
  • Unlimited personal secrets
  • 10 active shares
  • Community support
Start for free
most popular

Pro

For power users

$5/user/mo

or $50/user/yr

Everything in Free, plus:

  • Unlimited devices
  • Unlimited shares
  • Large file shares (up to 1 GB)
  • Advanced expiry & revocation controls
  • Priority support
Get Pro

Business

For teams

$10/seat/mo

or $100/seat/yr

Everything in Pro, plus:

  • Organizations & teams
  • Role-based access
  • Shared projects & environments
  • Team audit log with export
  • 5 machine identities per seat included
  • Admin controls
Start 14-day trial

14-day trial · no card required

Enterprise

For organizations at scale

Custom

Everything in Business, plus:

  • SSO / SCIM
  • DPA & custom agreements
  • Custom retention
  • Dedicated support
  • Self-hosting on the roadmap
Contact us

Zero-knowledge on every plan

Encryption happens on your device with keys we never see. Paid tiers raise limits; the security model is identical on all of them.

How zero-knowledge works →

Never locked out

If you downgrade or stop paying, your vault stays readable and export always works. Your secrets are yours.

Built for machines too

Business seats include machine identities so CI and servers get scoped, revocable access instead of long-lived tokens.

Pock for agents →

Questions, answered

You charge for this. Can you read my secrets on paid plans?+

No, on any plan. Every secret is encrypted on your device before it leaves, and the keys never touch our servers. Paying for Pock buys more capacity and team features; the security model is identical on every tier. Even if we were compelled to hand over our databases, there is nothing readable in them.

What is a machine identity?+

A machine identity is a non-human vault member, such as a CI pipeline or a deploy server, with its own key pair and its own scoped access. Instead of pasting a long-lived token into your CI config, you enroll the machine, grant it exactly the projects and environments it needs, and revoke it independently of any human. Business plans include 5 per seat; more can be added.

What happens if I stop paying?+

You are never locked out of your own secrets. Your vault stays readable and export always works. Downgrading only pauses plan features like unlimited shares or team management until you're back under the free limits. And because your data is encrypted with keys we never see, withholding it is not something we are capable of.

Can I self-host Pock?+

Self-hosting is on the roadmap for Enterprise. Because the encryption happens entirely on your devices, the server is a deliberately dumb zero-knowledge relay, which makes it a good candidate for running inside your own infrastructure. If this is a requirement for you, email hello@pock.sh and tell us about your setup.

Start with a vault that's actually yours

Free during beta, no card required. Export any time.

Create your vault →