What is SOPS?

An editor of encrypted configuration files supporting YAML, JSON, ENV, INI, and BINARY formats. Encrypts values and comments while keeping file structure visible, with access management through identities and support for offline (Age, PGP) and cloud-based (AWS KMS, GCP, Azure, Vault) key stores.

Independently observed

SOPS pricing

We don't have SOPS's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Pricing as of verify at live pricing ↗Independently observed
Open source

Open source and free

What SOPS does

The capabilities that matter for secrets management tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Core
Tool type
Secret store / engine
Dynamic (short-lived) secrets
Deployment
Hosting
Cloud + self-hosted
Lifecycle
Automatic secret rotation
Crypto
Encryption as a service (transit)
Compliance
FIPS 140-2/3 validated crypto
-
HSM support
-
Access
Fine-grained / identity-based policy
Governance
Audit logging
-
Integration
Kubernetes native (CRD / CSI / K8s auth)
-
Scope
PKI / certificate authority
-
Licensing
Open-source core
Ecosystem
CNCF maturity
Sandbox
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Cloud / SaaS
  • Self-hosted

Integrations (8)

Independently observed
  • Age
  • PGP/GnuPG
  • Amazon AWS KMS
  • Google Cloud KMS
  • Azure Key Vault
  • HuaweiCloud KMS
  • HashiCorp Vault
  • OpenBAO

SOPS alternatives

Other secrets management tools we track, ranked by the same independent score.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for SOPS, not the verdict.

Balanced composite 51 / 100
low · 18%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Github Activity470.105.0
Release Cadence760.064.4
Capabilities460.073.2
Github Stars820.032.4
Integrations270.071.9
Security Posture00.230.0-
Package Downloads00.150.0-
Stackoverflow Activity00.070.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d31mediumsource · 2026-08-01 · 65%

Adoption

AttributeValueEvidence
Github stars22,648highsource · 2026-08-01 · 90%

Features

AttributeValueEvidence
Capabilities{"hosting":"both","tool_type":"store","cncf_project":"sandbox","dynamic_secrets":false,"secret_rotation":false,"open_source_core":true,"fine_grained_policy":true,"encryption_as_a_service":false}mediumsource · 2026-08-05 · 60%

Integrations

AttributeValueEvidence
Count8mediumsource · 2026-08-05 · 60%

Language

AttributeValueEvidence
PrimaryGohighsource · 2026-08-01 · 90%

License

AttributeValueEvidence
SpdxMPL-2.0highsource · 2026-08-01 · 95%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-08-01 · 60%
Modelopen_sourcemediumsource · 2026-08-05 · 60%
Price levelfreemediumsource · 2026-08-05 · 60%
TransparentYesmediumsource · 2026-08-01 · 60%

Release

AttributeValueEvidence
Cadence days44mediumsource · 2026-08-01 · 70%