The Free-Forever Commitment

Every security feature is free. Forever.

Copywarden is a security product, and trust in a security product has to rest on something sturdier than marketing. This page is our permanent, public commitment about what is free, what we charge for, what you can verify without trusting us — and why none of it will quietly change later.

The parts of Copywarden that protect your data are free — not a trial, not a teaser, but the complete security feature set, permanently:

Encryption at rest

Every clipboard item is encrypted with AES-256-GCM before it touches disk.

Per-item key derivation

HKDF-SHA256 per-item keys from a random 256-bit master key (RFC 5869), so no two items share a key.

Secure Enclave key wrapping

On capable Macs the master key is stored wrapped by a non-extractable Secure Enclave key; Macs without one use Keychain-only, device-local, unlock-gated storage.

Secret detection and redaction

On-device scanning for credentials, tokens, and keys, with unconditional masking in previews.

The agent chokepoint

AgentAccessGuard — the single gate every automation surface must pass through. It never serves a detected secret, honors a kill-switch, and audits every access.

The tamper-evident audit log

HMAC-chained, so security-relevant events cannot be silently rewritten.

Local-Only mode

The switch that refuses every cloud and off-device transport, for air-gapped environments.

Screen-share detection and redaction

Detection of active screen capture and recording, and the preview redaction it triggers.

If a capability decides whether your clipboard data is safe, it belongs on this list, and it is free. You will never pay Copywarden for the security of your own data.

The business

What we charge for

Copywarden is a business, and we'd rather fund it with prices on a public page than with your data. Paid tiers cover the things that go beyond securing the data on your own Mac:

Sync and the Copywarden Account

End-to-end encrypted multi-device sync and the account infrastructure behind it.

Teams and shared pinboards

Multi-person collaboration on top of the encrypted core.

Compliance operations

The tooling around regulated deployments: SSO/SAML and SCIM provisioning, MDM fleet deployment, and audit-log export workflows for compliance review.

Pro conveniences

On-device AI search and compliance retention profiles, per the published pricing page.

The pattern: the security of one person's data on one Mac is free. Multi-device, multi-person, and fleet operations are the business.

The pledge

No bait and switch

The last few years taught software users a specific lesson about promises: communities were built on a generous deal, and then the deal changed. HashiCorp relicensed Terraform in 2023, Redis changed its license in 2024, Elastic did it in 2021 — and each time, the backlash wasn't really about legal terms. It was about the retroactive feeling that the generosity had been bait. A proprietary product's version of that failure is quieter but identical in kind: the free tier that erodes, the feature that migrates behind the paywall, the "telemetry-free" claim that gains an asterisk. We are writing this down precisely so you do not have to take our word for it later:

1. Security features never move from Free to paid

Every capability on the list above stays in the free tier, and new capabilities that decide whether your data is safe join the free tier when they ship.

2. The free tier is not a funnel with a fuse

No time limits, no item-count caps on the security features, no account requirement to keep using them.

3. Telemetry-free forever

No analytics, no usage tracking, no ads, no data sale — in any tier, free or paid. The product is the business model; your clipboard is not.

4. If we ever break this pledge, this page is the receipt

Its revisions are dated and published. Quote it against us.

Verification

What you can check without trusting us

Copywarden is proprietary software, so we don't ask you to trust the source — we point you at what you can check yourself.

The wire

Local-first and telemetry-free are network claims, and network claims are testable: point Little Snitch, LuLu, or any network monitor at Copywarden. With sync off, you will see zero outbound connections. With sync on, you can confirm that what leaves is opaque ciphertext bound for Apple's iCloud — not for a Copywarden server, because there isn't one.

The signature

Every build is Developer ID-signed and notarized by Apple, so the binary you run is the binary we shipped, unmodified.

The threat model

We publish it — including the residual risks we do not claim to solve — so our claims can be checked against our own stated limits.

The disclosure policy

Our single-shot incident-response policy is published in advance, written before it is ever needed.

And what you cannot check yet

Stated plainly: there has been no independent security audit and no bug bounty. When either exists we will say so here, with a date and a link — and not before.

Holding us to it

Revisions to this page are dated, and the changelog is published alongside it. If you believe a security feature has been paywalled, a network claim has quietly changed, or this pledge is being walked back, email security@copywarden.com and say so publicly. We intend this document to be quotable against us. This commitment does not expire.

Get Copywarden free