Engineering-led teams (20-1,000 employees) wanting an open-source modern secrets platform with cloud or self-host, without inheriting Vault operational complexity.
Regulated enterprises needing CyberArk Conjur-tier evidence trails or FedRAMP authorization, and organizations needing Vault-tier dynamic credentials breadth.
Is Infisical a trustworthy vendor?
- 2023-01-15Infisical accepted into Y Combinator W23Funded modern open-source secrets platform development.
- 2024-08-22Series A funding round led by Stripe-backed investorsFunded enterprise readiness and self-host commercial expansion.
- 2025-03-10SOC 2 Type 2 attestation completedRemoved a common enterprise-buyer blocker for cloud deployments.
What 140 reviews actually say
Synthesized from G2, Capterra, Reddit, Trustpilot. Patterns >15% prevalence shown.
Praise patterns
- MIT-licensed open-source core78% ↑
- Modern developer ergonomics rival Doppler71% ↑
- Self-host option strong post-HashiCorp BSL switch64% ↑
- Native Kubernetes integration is clean47% →
Complaint patterns
- Younger company; enterprise SLA depth still maturing38% ↓
- Smaller community and integration list31% ↓
- Dynamic credentials coverage narrower than Vault31% →
What buyers actually pay
31 anonymized deal disclosures · last updated 2026-05-01
| Company size | Median annual |
|---|---|
| 10-100 employees | $4,800 |
| 100-500 employees | $22,000 |
| 500+ employees | $78,000 |
Auto-verified certifications
Editorial: Strengths
- MIT-licensed open-source core; the cleanest OSS story among modern entrants
- Modern developer ergonomics (UI, CLI, branching environments)
- Y Combinator W23 momentum; product velocity above incumbents
- Self-host option positioned strongly post-HashiCorp BSL switch
- Native Kubernetes integration via Infisical Operator
- Open-source secret scanning included in the platform
Editorial: Weaknesses
- Younger company; enterprise SLA depth still maturing
- Smaller community and integration list than Vault or Doppler
- Dynamic credentials coverage narrower than Vault or Akeyless
- No PKI secrets engine; certificate lifecycle is not first-party
- Smaller verified-pricing dataset; deal-size predictability is lower
Key features & integrations
- +MIT-licensed open-source core
- +Static secrets with project, environment, folder hierarchy
- +Environment branching and overrides
- +Native Kubernetes integration via Infisical Operator
- +CLI and SDK coverage (Node, Python, Go, Java, .NET)
- +GitHub Actions, GitLab CI, CircleCI, Jenkins, Vercel integrations
- +Open-source secret scanning for repos and pipelines
- +Audit logs and granular RBAC
- +SSO/SAML and SCIM provisioning (Pro and Enterprise)
- +Self-host option for air-gapped deployments
Read our full ranking of Secrets Management Software
Infisical ranks #7 in our editorial review of 10 secrets management software platforms. The deep-dive covers methodology, comparison tables, decision matrix, migration scoring, and FAQs.
Read the full rankingClosest alternatives in Secrets Management Software
Contribute your verified deal price
Pricing in B2B software is opaque because vendors want it that way. Verified buyer prices fix that, anonymously. Share what you actually paid for Infisical; we’ll add it to the verified pricing dataset on this page (with company size band only, no identifying details).
Submit anonymously