Product comparison
Secretus vs 1Password
These are different categories, and we'll be honest about it: 1Password is an excellent password manager — vaults, autofill, team permissions — and if you need a place to store credentials long-term, use one. Secretus does not replace it.
Secretus is the transfer layer: getting a secret safely to someone else, especially outside your vault. 1Password stores an encrypted copy of a shared item on a dedicated Frankfurt server and supports expiry and optional view-once controls. Secretus requires the sender to create an account and start a trial, while recipients need no account; its one-time Standard mode, live P2P mode and hybrid post-quantum component address a different workflow.
Side by side
| Feature | Secretus | 1Password |
|---|---|---|
| Primary job | Secure one-time transfer | Credential storage (vault) |
| Long-term storage, autofill, browser extension | ||
| Sender access | Account + 14-day trial or paid plan | 1Password account/subscription |
| Recipient needs an account | No | No (for shared links) |
| One-time by default | Yes — link invalidated before payload response | Optional; expiry is configurable |
| Shared secret stored on a server | Ciphertext only — or not at all (P2P mode) | Encrypted copy on sharing server |
| Per-message key rotation for transfers | Yes (live mode) | |
| Post-quantum key agreement | Hybrid ML-KEM-768 (FIPS 203) | |
| Team k-of-n splitting (Shamir) | ||
| Hosting scope | Core origins and persistent stores in Frankfurt; global edge/providers | Shared copy on dedicated Frankfurt server |
When 1Password is the better fit
- • You need a password manager: storing credentials, autofill, shared team vaults, SSO integration.
- • Recipients are inside your organisation and already live in your vault structure.
When Secretus is the better fit
- • One-off transfers to recipients outside your org who should not need an account.
- • Secrets that must never persist: live P2P delivery with per-message key rotation, nothing stored.
- • Splitting a master credential across a team so no single person holds it (Shamir k-of-n).
- • Post-quantum protection for the transfer itself, against harvest-now-decrypt-later.
Frequently asked questions
Does Secretus replace 1Password?
No — they solve different jobs. Keep credentials in a password manager when you need long-term storage and autofill; use Secretus for one-time transfer workflows, especially to recipients outside your organisation.
Is 1Password's item sharing insecure?
No. 1Password documents client-side encryption of the shared copy, storage on a dedicated Frankfurt server, configurable expiry and optional view-once access. Secretus differs by making Standard-mode links one-time by default and offering a live P2P mode where the payload is not stored server-side.
Why use a transfer tool when I can just share from my vault?
Vault sharing works well inside an existing account structure. For outsiders, Secretus lets the recipient open a one-time link without an account, can deliver peer-to-peer without a server-side payload copy, and provides delivery confirmation. The sender does need a Secretus account and trial or paid access.
Start a 14-day trial to send; recipients can open one-time links without an account.
Share a secret nowComparison reflects publicly documented behaviour checked on 3 August 2026. Spotted an inaccuracy? Tell us and we'll fix it.
