Secretus logo

Product comparison

Secretus vs Yopass

Credit where due: Yopass gets the cryptography right. It encrypts in your browser, puts the decryption key in the URL fragment, and its server stores only ciphertext — the same zero-knowledge model Secretus uses for async secrets. If a friend asks for a simple, self-hostable secret-sharing tool, Yopass is a good answer.

The difference is architecture and packaging. Current Yopass editions include capabilities such as OIDC, audit logging, read receipts, secret requests and webhooks. Secretus differs through its live peer-to-peer mode, authenticated X3DH-style setup, per-message key rotation, hybrid post-quantum key agreement and Shamir k-of-n team splitting.

Side by side

FeatureSecretusYopass
Client-side encryption (browser)
Decryption key in URL fragment
Server stores only ciphertext
One-time linksDefault — metadata removed before delivery; object cleanup followsDefault one-time retrieval
Live P2P mode — secret not stored server-sideAuthenticated X3DH-style + WebRTC
Per-message key rotation in live mode
Post-quantum key agreementHybrid ML-KEM-768 (FIPS 203)
Team k-of-n splitting (Shamir)
Request a secret from someoneAvailable in current licensed editions
Audit log90 days Starter/Pro; 1 year BusinessAvailable in current licensed editions
Open source / self-hostableClient code runs unobfuscated; hosted EUYes — fully open source

When Yopass is the better fit

  • • You want a minimal, fully open-source tool you can self-host and audit end to end.
  • • You prefer Yopass's licensed OIDC, webhook and audit features in a self-hosted deployment.

When Secretus is the better fit

  • • You sometimes need the secret to never exist on any server — live P2P with per-message key rotation.
  • • You operate as a team: Shamir k-of-n split for shared credentials, secret requests, audit trail.
  • • You want post-quantum protection against harvest-now-decrypt-later, today.
  • • You want Secretus delivery confirmation and its claim-and-consume one-time read flow.

Frequently asked questions

Isn't Yopass just as secure as Secretus?

For async drop-a-secret sharing, the core model is similar: browser-side encryption, key in the fragment and ciphertext-only server storage. Current Yopass editions also offer OIDC, audit logs, read receipts, requests and webhooks. Secretus's distinct modes are authenticated hybrid P2P with per-message key rotation and Shamir k-of-n splitting.

What does the live P2P mode add over async sharing?

In live mode the encrypted secret travels directly between the two browsers over WebRTC and is never written to any server. Secretus rotates per-message encryption keys inside the live session; async tools, Yopass included, always leave ciphertext on a server until it's read or expires.

Why does post-quantum matter for a secret that self-destructs?

Ciphertext can be recorded in transit today and decrypted years from now once quantum computers mature — 'harvest now, decrypt later'. Secretus hybridises ECDH with ML-KEM-768 (NIST FIPS 203), so a future quantum adversary would have to break the post-quantum layer too, not just ECDH — reducing that harvest-now-decrypt-later risk rather than promising immunity.

Start a 14-day trial to send; recipients can open one-time links without an account.

Share a secret now

Comparison reflects publicly documented behaviour checked on 3 August 2026. Spotted an inaccuracy? Tell us and we'll fix it.