Every security feature is free. Forever.
Copywarden is a security product, and trust in a security product has to rest on something sturdier than marketing. This page is our permanent, public commitment about what is free, what we charge for, what you can verify without trusting us — and why none of it will quietly change later.
The parts of Copywarden that protect your data are free — not a trial, not a teaser, but the complete security feature set, permanently:
Encryption at rest
Every clipboard item is encrypted with AES-256-GCM before it touches disk.
Per-item key derivation
HKDF-SHA256 per-item keys from a random 256-bit master key (RFC 5869), so no two items share a key.
Secure Enclave key wrapping
On capable Macs the master key is stored wrapped by a non-extractable Secure Enclave key; Macs without one use Keychain-only, device-local, unlock-gated storage.
Secret detection and redaction
On-device scanning for credentials, tokens, and keys, with unconditional masking in previews.
The agent chokepoint
AgentAccessGuard — the single gate every automation surface must pass through. It never serves a detected secret, honors a kill-switch, and audits every access.
The tamper-evident audit log
HMAC-chained, so security-relevant events cannot be silently rewritten.
Local-Only mode
The switch that refuses every cloud and off-device transport, for air-gapped environments.
Screen-share detection and redaction
Detection of active screen capture and recording, and the preview redaction it triggers.
If a capability decides whether your clipboard data is safe, it belongs on this list, and it is free. You will never pay Copywarden for the security of your own data.
What we charge for
Copywarden is a business, and we'd rather fund it with prices on a public page than with your data. Paid tiers cover the things that go beyond securing the data on your own Mac:
Sync and the Copywarden Account
End-to-end encrypted multi-device sync and the account infrastructure behind it.
Teams and shared pinboards
Multi-person collaboration on top of the encrypted core.
Compliance operations
The tooling around regulated deployments: SSO/SAML and SCIM provisioning, MDM fleet deployment, and audit-log export workflows for compliance review.
Pro conveniences
On-device AI search and compliance retention profiles, per the published pricing page.
The pattern: the security of one person's data on one Mac is free. Multi-device, multi-person, and fleet operations are the business.
No bait and switch
The last few years taught software users a specific lesson about promises: communities were built on a generous deal, and then the deal changed. HashiCorp relicensed Terraform in 2023, Redis changed its license in 2024, Elastic did it in 2021 — and each time, the backlash wasn't really about legal terms. It was about the retroactive feeling that the generosity had been bait. A proprietary product's version of that failure is quieter but identical in kind: the free tier that erodes, the feature that migrates behind the paywall, the "telemetry-free" claim that gains an asterisk. We are writing this down precisely so you do not have to take our word for it later:
1. Security features never move from Free to paid
Every capability on the list above stays in the free tier, and new capabilities that decide whether your data is safe join the free tier when they ship.
2. The free tier is not a funnel with a fuse
No time limits, no item-count caps on the security features, no account requirement to keep using them.
3. Telemetry-free forever
No analytics, no usage tracking, no ads, no data sale — in any tier, free or paid. The product is the business model; your clipboard is not.
4. If we ever break this pledge, this page is the receipt
Its revisions are dated and published. Quote it against us.
What you can check without trusting us
Copywarden is proprietary software, so we don't ask you to trust the source — we point you at what you can check yourself.
The wire
Local-first and telemetry-free are network claims, and network claims are testable: point Little Snitch, LuLu, or any network monitor at Copywarden. With sync off, you will see zero outbound connections. With sync on, you can confirm that what leaves is opaque ciphertext bound for Apple's iCloud — not for a Copywarden server, because there isn't one.
The signature
Every build is Developer ID-signed and notarized by Apple, so the binary you run is the binary we shipped, unmodified.
The threat model
We publish it — including the residual risks we do not claim to solve — so our claims can be checked against our own stated limits.
The disclosure policy
Our single-shot incident-response policy is published in advance, written before it is ever needed.
And what you cannot check yet
Stated plainly: there has been no independent security audit and no bug bounty. When either exists we will say so here, with a date and a link — and not before.
Holding us to it
Revisions to this page are dated, and the changelog is published alongside it. If you believe a security feature has been paywalled, a network claim has quietly changed, or this pledge is being walked back, email security@copywarden.com and say so publicly. We intend this document to be quotable against us. This commitment does not expire.