Back to home

Three keeps, one price to compare

Compare plans

Pick how you want to run VaultGuard. Self host the source available Community edition on your own AWS for free, or let us run it for you on VaultGuard Cloud. Every plan ships with the same encryption, per file permissions, and key rotation on offboarding. Security is never behind a paywall.

Plans at a glance

CapabilityCommunitySelf host, freeProCloud, Pro EditionEnterpriseCloud, Pro Edition, single sign on
PriceFree, self host€12 per user per monthCustom
Where it runsYour own AWSOur AWS (managed)Dedicated infrastructure
LicenseSustainable Use LicenseCloud terms of serviceCommercial contract
User capUp to 100Up to 100Unlimited
StorageLimited by your AWS100 GB included1 TB
TrialClone and deploy14 day free trialSales call

Security you get on every plan

The same encryption, access controls, and offboarding guarantees, whether you self host or let us run it.

CapabilityCommunitySelf host, freeProCloud, Pro EditionEnterpriseCloud, Pro Edition, single sign on
Encryption at rest and in transit (AES 256 GCM, keys in AWS KMS)
Per file permissions with role inheritance
Visual permission graph and in Obsidian access management
Access revoked and keys rotated on offboarding
Time bound key leases (one hour default, configurable)
Multi vault support per organization
Plugin allowlist enforcement
Cognito auth (federate to your identity provider)
Local at rest encryption via OS keychain
TLS 1.2+ in transit

AI in your vault

Use AI on your notes through the same encryption, permissions, and audit gates, on every plan.

CapabilityCommunitySelf host, freeProCloud, Pro EditionEnterpriseCloud, Pro Edition, single sign on
Built in Claude chat panel (bring your own Anthropic key or Claude subscription)
AI agent bridge: a scoped MCP server for Claude Code, Cursor, or Claudian
Every AI file access permission checked and audit logged

Running it day to day

What you get back when we run the infrastructure for you.

CapabilityCommunitySelf host, freeProCloud, Pro EditionEnterpriseCloud, Pro Edition, single sign on
In Obsidian admin (users, permissions, settings, recovery)
Hosted web admin panel (admin.vaultguard.cloud)
Share links: send a teammate a clickable link to a specific file
Basic audit log
Advanced audit: dashboards, alerts, CSV export, per user and per file reports
Audit retention30 days (configurable)1 yearCustom
Stripe backed billing
Transactional email (invites, password reset)Your SESManagedManaged
Org signupSingle tenant lockdownMulti tenantCustom
Managed AWS infrastructure
Managed security update process
Managed backup operations
Uptime targetNone99.9 percent targetCustom by agreement
Support targetCommunity (GitHub)Email, one business day targetPriority by agreement

Enterprise only

CapabilityCommunitySelf host, freeProCloud, Pro EditionEnterpriseCloud, Pro Edition, single sign on
SAML and OIDC single sign on
SOC 2 and HIPAA evidence packagesAvailable by agreement
Dedicated infrastructure
Custom data residency
Custom key rotation and retention policies

Who handles what

What stays on your plate if you self host, and what we take off it on Cloud.

CapabilityCommunitySelf host, freeProCloud, Pro EditionEnterpriseCloud, Pro Edition, single sign on
Deploy the backendYou (terraform apply)UsUs, or you with a license
Patch Lambda runtimes and dependenciesYouUsUs
Rotate KMS keysYouUsUs or custom
Run backupsYouUsUs
Monitor uptime and page on callYouUsUs
Pay the AWS billYouIncludedCustom
Compliance evidenceYouIncludedUs

Which plan fits you?

For most teams, Pro is the best place to start. You get the full security stack, admin panel, user permissions, secure note sharing, readable audit trails, managed backup operations, and a 99.9 percent uptime target, without managing AWS yourself.

Start free and see it for yourself

Choose Community only if you are a solo user or a technical team that wants to self host and manage AWS, backups, patches, and uptime yourself.

Choose Enterprise if you need single sign on or dedicated infrastructure.

What you get if you self host

  • The same encryption, per file permissions, and key rotation on offboarding as Pro
  • Your data stays in your own AWS account
  • The same plugin connects automatically, no special build
  • One command Terraform deploy, and the infrastructure code is open for you to audit
  • Cost: just your AWS bill
  • You are the on call: patching Lambda runtimes, rotating KMS keys, running backups, and monitoring uptime is on you

What is not included when you self host

  • No web admin panel. Every user invite, permission change, and recovery flow happens inside Obsidian, which gets painful past a handful of users
  • No share links. Teammates cannot get a one click link to a specific note, they navigate the folder tree themselves
  • No audit dashboards, alerts, or CSV exports when your compliance team asks for an audit trail
  • No managed uptime commitment, backup operations, or patch pipeline. AWS deprecations and incident response land on you
  • Single sign on is available only on Enterprise