Armor ⛨

Pricing

Dotenvx is free and open source. But you can pay for Dotenvx Armor.

Plan Users Audit retention Price
Pro 1 5 days $5 Get Pro
Team 3 30 days $20 Get Team
Business 10 90 days $90 Get Business
Enterprise Custom Custom Contact Us

Access & Identity

Feature Pro Team BusinessBiz EnterpriseEnt
Users 1 3 10
Solo Security
Team Security
Automation Tokens

Security

Feature Pro Team BusinessBiz EnterpriseEnt
Armored Keys Unlimited Unlimited Unlimited Unlimited
Guard Keys
Enclave Keys
Rotate Keys ManualMan CommandCmd CommandCmd CommandCmd
Audit Logs
Audit Events 25,00025k 250,000250k 1,000,0001M Custom
Audit Retention 5 days 30 days 90 days
SIEM / Log Export

Customer Support

Feature Pro Team BusinessBiz EnterpriseEnt
Billing MonthlyMo MonthlyMo MonthlyMo FlexibleFlex
Payment Card Card Card FlexibleFlex
Ticket Support
Slack Support
Dotenvx Expertise
Urgent Response SLA
Priority Security Updates

FAQ

  • Is dotenvx free? Yes. dotenvx is free and open source. You can encrypt, decrypt, and run with .env files at no cost. Armor is optional paid infrastructure for key custody, access control, and audit logs when you want that layer of protection.
  • What are audit logs? Armor records each key access across your workspace—who accessed what, and when. Pro includes 25,000 audited accesses per month with 5-day retention, Team includes 250,000 with 30-day retention, and Business includes 1 million with 90-day retention.
  • What happens if I exceed the included audited accesses? Key access keeps working. Additional audited accesses are billed as overages, with usage alerts before charges begin. Pro is $0.20, Team is $0.10, and Business is $0.025 per additional 1,000 audited accesses.
  • Are armored keys limited? No. Every plan includes unlimited armored keys. You pay for users and how long you keep the audit trail—not for how many keys you protect.
  • How does encryption work? Dotenvx uses ECIES to encrypt each secret with a unique ephemeral key. The public key encrypts; Armor secures the long-term private key, controls who can access it, and records each access in your audit trail. Read the whitepaper for details.
  • Is it safe to commit an encrypted .env file? Yes. Even if the encrypted file is exposed, secrets stay protected without the separate private key. Breaking that requires brute-forcing AES-256 and elliptic curve crypto. Read the whitepaper for details.
  • How does it protect me from incidents like Vercel’s? If an attacker accesses environment variables, they still cannot decrypt your encrypted .env secrets without the separate private decryption key.