The difference is the billing unit.
Doppler and Infisical are good tools, and this page says so in the rows where they beat us. What separates the three of us is what gets counted when the invoice is drawn.
One team. 5 engineers who sign in, 47 machines that never will.
Same estate, three billing models, three monthly bills. The gap is not a discount, it is a definition.
Competitor figures are their public list prices as of August 2026, at the plan named under each. Ours comes from the same price book checkout charges from.
- penv-cloud
- $90
- Doppler
- $105
- Infisical
- $1040
5 seats
5 users, Team
52 identities, Pro
Every row, including the ones we lose.
Verified against each vendor's own pricing page and docs, and against our own source. Where a claim could not be checked, it is not here.
| As of August 2026 | penv-cloud | Doppler | Infisical |
|---|---|---|---|
| Billing unit | Per human seat | Per user seat | Per identity, human or machine¹ |
| Machines on the invoice | Free and unlimited | Service tokens capped by tier | Every machine identity is billable |
| Headline price / mo | $18 annual · $22 monthly | $21 per user (Team)² | $20 per identity (Pro, annual)² |
| Per-seat add-ons | None | Custom roles, groups, syncs: +$9 each³ | Dynamic secrets need the $40 tier⁴ |
| Keyless CI auth (OIDC) | Every plan, including Free | Team and Enterprise, since March 2025⁵ | Yes, and a broad auth matrix |
| Audit retention, free tier | 7 days, insert-only | 3 days⁶ | 30 days from Pro⁶ |
| Encryption at rest | Envelope + AWS KMS, every plan | Tokenized, AES-256-GCM, GCP KMS | AES-256-GCM, server-side KMS |
| Ciphertext bound to its address | AAD over the full address⁷ | Not documented | Not documented |
| Customer-held keys | Your AWS, GCP, Azure or Vault key on Enterprise⁸ | Enterprise Key Management | External KMS / HSM on Enterprise |
| Self-hosting | Cloud only | Cloud only | MIT core, self-hostable |
| Compliance certifications | SOC 2 in progress | SOC 2 Type II, ISO 27001 | SOC 2 Type II |
| Trust model | Server-side envelope⁹ | Server-side | Server-side⁹ |
- 1.Infisical's own definition, from their pricing page: "An identity is any human or machine that authenticates to Infisical." Billing is per identity object rather than per pipeline run.
- 2.Competitor list prices as of August 2026, monthly equivalents. Infisical's $20 is the annual rate; monthly is $23. We compare published prices rather than negotiated deals.
- 3.Doppler's Team plan sells custom roles, user groups, and integration syncs as separate $9/seat/month add-ons. They are standard on Enterprise.
- 4.Infisical places dynamic secrets on its Advanced tier at $40 per identity per month. Ours are on every plan, with one integration connection on Free.
- 5.Doppler does offer keyless OIDC auth, as Service Account Identities added in March 2025, on Team and Enterprise. The difference we are naming is which plan you need, not whether the capability exists.
- 6.Doppler: 3 days free, 90 days on Team. Infisical: 30 days included from Pro. Check each vendor's current pricing page before relying on a number.
- 7.The additional authenticated data is the full parameter address, so a ciphertext moved to another environment or organization fails to decrypt. Neither competitor documents an equivalent, which is not the same as neither having one.
- 8.All three wrap a data key with a key you control, and in all three the sealed data still lives on the vendor's infrastructure — none of this is zero-knowledge. We support AWS KMS, GCP Cloud KMS, Azure Key Vault and HashiCorp Vault Transit — the Vault must be reachable from the internet, as we cannot dial into a private network. Doppler supports AWS and GCP; Infisical adds HSM and KMIP.
- 9.Our server can decrypt your values to serve them to your machines. Infisical disabled end-to-end encryption by default and now holds keys server-side, as we do. None of the three of us is zero-knowledge. Read the security page →
Where they beat us.
Doppler
- SOC 2 Type II, ISO 27001, with a public trust center. Ours is in progress.
- A wider integration catalogue, a mature Kubernetes operator, and a Terraform provider. We ship no operator — Kubernetes reads from us through External Secrets Operator instead.
Infisical
- An MIT-licensed core you can self-host and read. We are cloud only.
- The broadest machine-auth matrix of the three, including SPIFFE and native cloud attestation.
- Around 31 dynamic-secret backends against our smaller set, and SOC 2 Type II today.
Whether this is for you.
Choose us when
- Your machines outnumber your engineers and the invoice keeps noticing.
- You want CI to authenticate by OIDC without paying for the privilege.
- You already run penv and want the hosted provider rather than a new mental model.
- You are leaving one of these two — we import from both, one way, and say what a migration loses.
- You want a vendor that publishes what it has not built.
Choose a competitor when
- Your Vault or key service is only reachable on a private network — we cannot dial into one.
- You need to self-host, or you need data residency in a named region.
- Your procurement gate is a completed SOC 2 report rather than one in progress.
How we source this