Security and privacy decision

SecretDrop

A single competent developer can implement a secure, password-based encrypted-bundle service (the core paid plan) in about a week and operate it with modest monthly maintenance; advanced Direct Transfer/key-management features would add complexity but are not required for a useful replacement.

Visit website

Built by Aleksandar Jovanovic, who ships 7 products in this index

You pay

$6.58/mo

$79/yr

Read off the official pricing page.

You’d pay instead

$50one-off21 h to build

$15/mo3 h/mo upkeep

On cash alone, building overtakes the subscription at 3 seats.

Open-source builds that already do this

Every project below is open source and already does this job today. Fork one, self-host it, or take the parts you need - the build prompt further down assumes an empty file, and this is the shortcut past that. Licences differ; check the one on each card before you ship. All SecretDrop alternatives, with the arithmetic →

What a replacement has to do

  • Encrypt files in the browser, upload encrypted blobs to server storage, generate a short shareable link with expiry and download limits, recipient opens link and decrypts in-browser using password.

What it still won’t have

  • Built-in end-to-end direct transfer to registered users (per-recipient public-key encryption and key management)
  • Polished multi-user dashboard and full analytics feature-parity
  • Official VS Code extension and CLI integrations (coming soon)
  • Hosted lifetime plan and vendor support/updates

What remains hard

  • Product polish and ongoing maintenance
Read the build prompt

First-year cost

Keep paying

Paying is—cheaper in year one.

On cash alone, building overtakes the subscription at 3 seats.

Paid seatsseats

Money you would actually spend

Keep paying
—

Subscription price × seats × 12

Build it
—

AI build —APIs + hosting —

Time you would spend

—

—

What you would spend

What we assumed

The verdict above measures whether you could build it. This one is only about money.

Runnable build prompt

Not run yet
Build a minimal SecretDrop replacement: frontend in React (Vite) using Web Crypto API for AES-256-GCM encryption and PBKDF2 key derivation; backend in Node.js + Express with PostgreSQL for metadata and access logs; store encrypted blobs in S3-compatible storage; implement endpoints to create bundles (accept encrypted blob upload, store metadata, generate unguessable link token and store password verification hash), retrieve bundles (verify token and password hash, increment download counters, serve blob URL), background worker to expire/delete bundles by TTL and enforce download limits, and a small dashboard page showing bundle list and access events. Out of scope: per-recipient public-key Direct Transfer, enterprise billing, and VS Code/CLI integrations. Include error handling, unit tests for crypto and API endpoints, integration tests for upload/download flows, and Docker-based deployment manifests.
How we checked3 sources · 2/3 runs agreed · evidence score 89

How the score was reached

  • Build verdict base78
  • An open-source build was found+5
  • 3 cited sources+3
  • Price verified on pricing page+3
  • Evidence score89

The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.

How scoring works →

Cited sources · 3

Every page the run actually retrieved.

Integrity checks

What held up, and what did not.

✓ Price read off the page! 2 of 3 runs agreed; the verdict is the majority✓ Citations limited to fetched pages! 1 moat recorded