Product comparison
Secretus vs Yopass
Credit where due: Yopass gets the cryptography right. It encrypts in your browser, puts the decryption key in the URL fragment, and its server stores only ciphertext — the same zero-knowledge model Secretus uses for async secrets. If a friend asks for a simple, self-hostable secret-sharing tool, Yopass is a good answer.
The difference is architecture and packaging. Current Yopass editions include capabilities such as OIDC, audit logging, read receipts, secret requests and webhooks. Secretus differs through its live peer-to-peer mode, authenticated X3DH-style setup, per-message key rotation, hybrid post-quantum key agreement and Shamir k-of-n team splitting.
Side by side
| Feature | Secretus | Yopass |
|---|---|---|
| Client-side encryption (browser) | ||
| Decryption key in URL fragment | ||
| Server stores only ciphertext | ||
| One-time links | Default — metadata removed before delivery; object cleanup follows | Default one-time retrieval |
| Live P2P mode — secret not stored server-side | Authenticated X3DH-style + WebRTC | |
| Per-message key rotation in live mode | ||
| Post-quantum key agreement | Hybrid ML-KEM-768 (FIPS 203) | |
| Team k-of-n splitting (Shamir) | ||
| Request a secret from someone | Available in current licensed editions | |
| Audit log | 90 days Starter/Pro; 1 year Business | Available in current licensed editions |
| Open source / self-hostable | Client code runs unobfuscated; hosted EU | Yes — fully open source |
When Yopass is the better fit
- • You want a minimal, fully open-source tool you can self-host and audit end to end.
- • You prefer Yopass's licensed OIDC, webhook and audit features in a self-hosted deployment.
When Secretus is the better fit
- • You sometimes need the secret to never exist on any server — live P2P with per-message key rotation.
- • You operate as a team: Shamir k-of-n split for shared credentials, secret requests, audit trail.
- • You want post-quantum protection against harvest-now-decrypt-later, today.
- • You want Secretus delivery confirmation and its claim-and-consume one-time read flow.
Frequently asked questions
Isn't Yopass just as secure as Secretus?
For async drop-a-secret sharing, the core model is similar: browser-side encryption, key in the fragment and ciphertext-only server storage. Current Yopass editions also offer OIDC, audit logs, read receipts, requests and webhooks. Secretus's distinct modes are authenticated hybrid P2P with per-message key rotation and Shamir k-of-n splitting.
What does the live P2P mode add over async sharing?
In live mode the encrypted secret travels directly between the two browsers over WebRTC and is never written to any server. Secretus rotates per-message encryption keys inside the live session; async tools, Yopass included, always leave ciphertext on a server until it's read or expires.
Why does post-quantum matter for a secret that self-destructs?
Ciphertext can be recorded in transit today and decrypted years from now once quantum computers mature — 'harvest now, decrypt later'. Secretus hybridises ECDH with ML-KEM-768 (NIST FIPS 203), so a future quantum adversary would have to break the post-quantum layer too, not just ECDH — reducing that harvest-now-decrypt-later risk rather than promising immunity.
Start a 14-day trial to send; recipients can open one-time links without an account.
Share a secret nowComparison reflects publicly documented behaviour checked on 3 August 2026. Spotted an inaccuracy? Tell us and we'll fix it.
