Compare

The difference is the billing unit.

Doppler and Infisical are good tools, and this page says so in the rows where they beat us. What separates the three of us is what gets counted when the invoice is drawn.

The arithmetic

One team. 5 engineers who sign in, 47 machines that never will.

Same estate, three billing models, three monthly bills. The gap is not a discount, it is a definition.

Competitor figures are their public list prices as of August 2026, at the plan named under each. Ours comes from the same price book checkout charges from.

penv-cloud
$90

5 seats

Doppler
$105

5 users, Team

Infisical
$1040

52 identities, Pro

Side by side

Every row, including the ones we lose.

Verified against each vendor's own pricing page and docs, and against our own source. Where a claim could not be checked, it is not here.

As of August 2026penv-cloudDopplerInfisical
Billing unitPer human seatPer user seatPer identity, human or machine¹
Machines on the invoiceFree and unlimitedService tokens capped by tierEvery machine identity is billable
Headline price / mo$18 annual · $22 monthly$21 per user (Team)²$20 per identity (Pro, annual)²
Per-seat add-onsNoneCustom roles, groups, syncs: +$9 each³Dynamic secrets need the $40 tier⁴
Keyless CI auth (OIDC)Every plan, including FreeTeam and Enterprise, since March 2025⁵Yes, and a broad auth matrix
Audit retention, free tier7 days, insert-only3 days⁶30 days from Pro⁶
Encryption at restEnvelope + AWS KMS, every planTokenized, AES-256-GCM, GCP KMSAES-256-GCM, server-side KMS
Ciphertext bound to its addressAAD over the full address⁷Not documentedNot documented
Customer-held keysYour AWS, GCP, Azure or Vault key on Enterprise⁸Enterprise Key ManagementExternal KMS / HSM on Enterprise
Self-hostingCloud onlyCloud onlyMIT core, self-hostable
Compliance certificationsSOC 2 in progressSOC 2 Type II, ISO 27001SOC 2 Type II
Trust modelServer-side envelope⁹Server-sideServer-side⁹
  1. 1.Infisical's own definition, from their pricing page: "An identity is any human or machine that authenticates to Infisical." Billing is per identity object rather than per pipeline run.
  2. 2.Competitor list prices as of August 2026, monthly equivalents. Infisical's $20 is the annual rate; monthly is $23. We compare published prices rather than negotiated deals.
  3. 3.Doppler's Team plan sells custom roles, user groups, and integration syncs as separate $9/seat/month add-ons. They are standard on Enterprise.
  4. 4.Infisical places dynamic secrets on its Advanced tier at $40 per identity per month. Ours are on every plan, with one integration connection on Free.
  5. 5.Doppler does offer keyless OIDC auth, as Service Account Identities added in March 2025, on Team and Enterprise. The difference we are naming is which plan you need, not whether the capability exists.
  6. 6.Doppler: 3 days free, 90 days on Team. Infisical: 30 days included from Pro. Check each vendor's current pricing page before relying on a number.
  7. 7.The additional authenticated data is the full parameter address, so a ciphertext moved to another environment or organization fails to decrypt. Neither competitor documents an equivalent, which is not the same as neither having one.
  8. 8.All three wrap a data key with a key you control, and in all three the sealed data still lives on the vendor's infrastructure — none of this is zero-knowledge. We support AWS KMS, GCP Cloud KMS, Azure Key Vault and HashiCorp Vault Transit — the Vault must be reachable from the internet, as we cannot dial into a private network. Doppler supports AWS and GCP; Infisical adds HSM and KMIP.
  9. 9.Our server can decrypt your values to serve them to your machines. Infisical disabled end-to-end encryption by default and now holds keys server-side, as we do. None of the three of us is zero-knowledge. Read the security page →
Credit where it is due

Where they beat us.

Doppler

  • SOC 2 Type II, ISO 27001, with a public trust center. Ours is in progress.
  • A wider integration catalogue, a mature Kubernetes operator, and a Terraform provider. We ship no operator — Kubernetes reads from us through External Secrets Operator instead.

Infisical

  • An MIT-licensed core you can self-host and read. We are cloud only.
  • The broadest machine-auth matrix of the three, including SPIFFE and native cloud attestation.
  • Around 31 dynamic-secret backends against our smaller set, and SOC 2 Type II today.
Fit

Whether this is for you.

Choose us when

  • Your machines outnumber your engineers and the invoice keeps noticing.
  • You want CI to authenticate by OIDC without paying for the privilege.
  • You already run penv and want the hosted provider rather than a new mental model.
  • You are leaving one of these two — we import from both, one way, and say what a migration loses.
  • You want a vendor that publishes what it has not built.

Choose a competitor when

  • Your Vault or key service is only reachable on a private network — we cannot dial into one.
  • You need to self-host, or you need data residency in a named region.
  • Your procurement gate is a completed SOC 2 report rather than one in progress.

How we source this

Every competitor figure comes from that vendor's own public pricing page or docs, checked in August 2026 and footnoted above. Pricing changes, so verify before you decide. Our own claims link to the security page, which names what our server can do with your values and what we have not built.

Get your keys out of the chat.

Three people free. Machines never take a seat.