Frequently Asked Questions
Find answers to common questions about IGETIS KeyVault
Pricing & Billing
Plans, payments, and refunds
All plans include:
- Support & SLA from day one - No extra fees for support
- AES-256 encryption at rest
- Role-based access control (RBAC)
- Audit logs
- SDK access for .NET (NuGet), Node.js (npm) and Java (Maven Central)
- AI-powered secret generation, anomaly detection & vault search
- 99.5%+ uptime guarantee
- 30-day money-back guarantee
Plans differ in user limits, project counts, secrets storage, response times, and advanced features like SSO. View detailed comparison
We offer a 30-day money-back guarantee instead of a traditional free trial. Here's why we think this is better:
- ✅ Full access to all features immediately
- ✅ Guaranteed support from day one
- ✅ No credit card required limitations
- ✅ No pressure to decide in 14 days
- ✅ Use it in production with confidence
It's simple and truly no questions asked:
- Subscribe to any plan
- Use KeyVault for up to 30 days
- If you're not satisfied for any reason, email our commercial partner at [email protected]
- We'll process your refund within 5 business days
We may ask for feedback to help improve our product, but your refund isn't conditional on providing it.
You can upgrade anytime! However, we do not allow mid-cycle downgrades to ensure service quality and data integrity.
✅ Upgrading (e.g., Startup → Standard)
- ✅ Allowed anytime
- ✅ Takes effect immediately
- ✅ You're charged a prorated amount for the remainder of your billing cycle
- ✅ All new features become available instantly
- ✅ Your new limits apply right away
- ✅ No disruption to your service
❌ Downgrading (e.g., Standard → Startup)
Downgrades are not permitted during your current billing cycle. Here's why:
- 🔒 Data integrity: Prevents data loss from exceeded limits
- 🔒 Service continuity: Avoids disruption to your production systems
- 🔒 Complexity management: Eliminates conflicts with existing usage
Option 1: Don't renew at current tier (Recommended)
- Continue using your current plan until the end of billing period
- Before renewal date, cancel your current subscription
- Immediately subscribe to the lower-tier plan you want
- You maintain service continuity with no gap
- Example: On Standard (renews Jan 31) → Cancel before Jan 31 → Subscribe to Startup on Jan 31
- Cancel your current subscription (keeps access until period ends)
- Export all your data before cancellation
- Subscribe to lower tier when ready
- Re-import your data
- Continue with current plan until it naturally expires
- Choose not to auto-renew
- Subscribe to lower tier after current period ends
💡 Consider These Alternatives First
Before deciding to move to a lower tier, consider:
- Reduce add-ons: Remove extra users, projects, or secrets instead
- Optimize usage: Delete unused secrets, archive old projects
- Switch to annual billing: Save 20% and keep your current features
- Talk to us: We might have a solution that works better for you
⚠️ Important Before Moving to Lower Tier
Make sure your usage fits within the lower tier's limits:
| Plan | Users | Projects | Secrets |
|---|---|---|---|
| Startup | 2 | 3 | 50 |
| Standard | 5 | 10 | 200 |
| Business Plus | 10 | 25 | 500 |
| Enterprise | 20 | 50 | 1,000 |
Need help? Contact [email protected] and we'll help you plan the best transition strategy for your needs.
We accept all major payment methods through Revolut:
💳 All Credit & Debit Cards (All Plans)
We accept virtually all card types through Revolut:
- ✅ Visa
- ✅ Mastercard
- ✅ American Express
- ✅ Maestro
- ✅ Discover
- ✅ Diners Club
- ✅ JCB
- ✅ UnionPay
- ✅ Any other Visa/Mastercard-branded cards worldwide
🌍 If your card works online, we can accept it!
🏦 Bank Transfer / Direct Debit (Annual Plans Only)
- Business Plus (annual): UK bank transfer available
- Enterprise (annual): International wire transfer + SEPA (EU)
- ⏰ Payment processed within 3-5 business days
- 📧 Contact [email protected] to arrange
📄 Purchase Orders (Enterprise Only)
- Available for Enterprise annual plans
- Net 30 payment terms
- Requires credit approval
- 📧 Email [email protected] to request
💰 Alternative Payment Methods
- Apple Pay: Available through Revolut checkout
- Google Pay: Available through Revolut checkout
- Digital Wallets: Most major digital wallets supported
- Cryptocurrency: Not currently supported
- All payments processed securely through Revolut
- Revolut is FCA regulated (UK Financial Conduct Authority)
- PCI DSS compliant payment processing
- We never store your payment information on our servers
- 3D Secure (3DS) authentication for added security
- Strong Customer Authentication (SCA) compliant for EU transactions
- Automatic receipts emailed after each payment
🌍 International Payments & Currency
We support customers worldwide:
- Primary currency: GBP (£) - British Pounds
- Automatic conversion available: USD ($), EUR (€), and 150+ other currencies
- Exchange rate: Real-time Revolut rates (typically better than traditional banks)
- Your card will be charged in your local currency or the currency you select
- No foreign transaction fees from our side (check with your bank)
- Multi-currency support: Pay in the currency most convenient for you
💡 Why Revolut?
- ✅ Accepts more card types than traditional processors
- ✅ Better exchange rates for international customers
- ✅ Faster payment processing
- ✅ Lower fees = better prices for you
- ✅ Instant payment confirmation
- ✅ Modern, secure payment infrastructure
Automatic invoicing for all customers:
📧 Invoice Delivery
- Emailed automatically after each successful payment
- Available in your dashboard under "Billing → Invoices"
- Downloadable as PDF
- Historical invoices available for 7 years
📝 Invoice Details Included
- Invoice number (unique reference)
- Billing period
- Plan details and quantities
- Subtotal, VAT/tax (if applicable), and total
- Payment method used
- Your company details (if provided)
🏢 Company Invoices / VAT
- Add company details: Settings → Billing → Company Information
- VAT number: Add your VAT registration number to have VAT shown separately
- UK VAT: 20% added for UK businesses without valid VAT number
- EU VAT: Reverse charge mechanism applies with valid VAT number
- Non-EU: No VAT charged
🔄 Billing Cycle
- Monthly: Charged on the same day each month (e.g., if you subscribe on 15th, charged on 15th)
- Annual: Charged once per year on anniversary date
- Prorated charges: When upgrading mid-cycle, you're charged the difference prorated
Failed Payments:
- We'll retry automatically 3 times over 7 days
- You'll receive email notifications before each retry
- Update payment method in dashboard to avoid service interruption
- Grace period: 14 days total before account suspension
Yes! Save 20% by paying annually:
| Plan | Monthly Price | Annual Price | You Save |
|---|---|---|---|
| Startup | £19.99/mo (£239.88/yr) | £191.90/yr | £47.98 |
| Standard | £49.99/mo (£599.88/yr) | £479.90/yr | £119.98 |
| Business Plus | £99.99/mo (£1,199.88/yr) | £959.90/yr | £239.98 |
| Enterprise | £249.99/mo (£2,999.88/yr) | £2,399.90/yr | £599.98 |
We handle overages gracefully with notifications and grace periods:
📊 Soft Limits (Users, Projects, Secrets)
How it works:
- 80% capacity: Email notification + dashboard banner
- 95% capacity: Second warning email
- 100% capacity: Final warning + 7-day grace period
- After grace period: Soft block (read-only until you upgrade or reduce usage)
You're on Startup plan (50 secrets limit):
- At 40 secrets (80%): "You're approaching your limit"
- At 48 secrets (95%): "Only 2 secrets remaining"
- At 50 secrets (100%): "Limit reached. You have 7 days to upgrade or delete secrets"
- After 7 days: Can't add new secrets until you upgrade or delete existing ones
⚡ Hard Limits (API Calls)
How it works:
- Approach limit: Email at 80% and 95%
- Exceed limit: API requests are throttled (slowed down), not blocked
- Rate limiting: Requests queued and processed at reduced speed
- Critical operations: Secret retrieval always works (admin operations may be throttled)
💰 Options When You Exceed Limits
Option 1: Upgrade to Next Tier (Recommended)
- ✅ Best value for money
- ✅ Immediate effect
- ✅ Get additional features
- ✅ Prorated billing (only pay difference)
Option 2: Purchase Add-ons
- +50 secrets: £9.99/month
- +5 users: £14.99/month
- +10 projects: £19.99/month
- +100K API calls: £9.99/month
Option 3: Reduce Usage
- Delete unused secrets
- Remove inactive users
- Archive old projects
- Optimize API call caching
📈 Comparison Example
| Scenario | Cost | What You Get |
|---|---|---|
| Startup + Add-ons (+50 secrets, +5 users) |
£44.97/mo | 100 secrets, 8 users, 24h support |
| Upgrade to Standard (Better value!) |
£49.99/mo | 200 secrets, 8 users, 12h support, more projects |
💡 Pro tip: Upgrade proactively when you hit 80% capacity to avoid disruptions. You can always downgrade later if needed.
Getting Started
Setup and onboarding
5 minutes or less! Here's the timeline:
- Sign up: 1 minute
- Create a project: 30 seconds
- Generate API credentials: 30 seconds
- Install SDK (.NET, Node.js or Java): 1 minute
- Add configuration: 2 minutes
No! That's one of our biggest advantages. KeyVault is designed to work anywhere:
- ✅ No Azure subscription required
- ✅ No AWS account needed
- ✅ No cloud-specific knowledge required
- ✅ Works on-premises, in any cloud, or hybrid
- ✅ Simple REST API + SDKs for .NET, Node.js & Java
If you know .NET, Node.js, or Java, you can use KeyVault. It's that simple.
Yes, and we make it easy!
Standard and above: Email migration assistance
Business Plus: Migration guidance call with our team
Enterprise: Full migration service included
Migration process:
- Export secrets from Azure/AWS (we provide scripts)
- Import to KeyVault via our bulk upload tool
- Update your application configuration
- Test in staging environment
- Switch production traffic
Average migration time: 2-4 hours for most applications.
We provide multiple resources:
- 📚 Documentation: Comprehensive guides at docs
- 🎥 Video tutorials: Step-by-step setup videos
- 💬 Email support: Available on all plans
- 📞 Onboarding call: Business Plus and Enterprise plans
- 🤝 Dedicated onboarding: Enterprise plans get hands-on assistance
Our average response time to setup questions: 4 hours (Standard plan and above).
Technical Questions
Integration and compatibility
IGETIS KeyVault provides official SDKs for three major ecosystems:
- ✅ .NET 6, 7, 8, 9 — NuGet package
IGETIS.KeyvaultSecret.AspNetCore - ✅ Node.js 18+ — npm package
@igetis/keyvaultwith NestJS support - ✅ Java 17+ — Maven Central
online.igetis.keyvault:keyvaultwith Spring Boot auto-configuration
Legacy .NET support:
- ⚠️ .NET Core 3.1 (best-effort support, not officially maintained)
- ❌ .NET Framework 4.x (not supported — use our REST API directly)
All SDKs use the same three credentials: TenantId, ClientId, Secrets.
Yes! IGETIS KeyVault is now truly multi-platform with official SDKs for all major stacks:
- 🟣 .NET / ASP.NET Core —
Install-Package IGETIS.KeyvaultSecret.AspNetCore - 🟢 Node.js / NestJS —
npm install @igetis/keyvault - 🟠 Java / Spring Boot —
online.igetis.keyvault:keyvault:1.0.0
For other languages (Python, Go, Ruby, PHP, Rust), you can use our REST API directly. All three credentials (TenantId, ClientId, Secrets) work the same way across all integrations.
API call limits by plan:
| Plan | Included API Calls/Month | Rate Limit |
|---|---|---|
| Startup | 25,000 | 100 requests/minute |
| Standard | 100,000 | 300 requests/minute |
| Business Plus | 500,000 | 1,000 requests/minute |
| Enterprise | Unlimited | 10,000 requests/minute |
Pro tip: All our SDKs (.NET, Node.js, Java) include built-in caching to minimize API calls.
Yes! Every time you update a secret, we automatically create a new version:
- Startup: Keep last 10 versions
- Standard: Keep last 30 versions
- Business Plus: Keep last 50 versions
- Enterprise: Unlimited version history
You can:
- ✅ View full version history
- ✅ Roll back to any previous version
- ✅ Compare versions side-by-side
- ✅ See who made changes and when
This is essential for audit compliance and disaster recovery.
Yes! We support bulk import from:
- 📄 appsettings.json (.NET) / application.yml (Java) / .env (Node.js)
- 📄 .env files
- 📄 CSV files
- 📄 JSON files
How to import:
- Go to your project in the dashboard
- Click "Import Secrets"
- Upload your file
- Review and confirm
You can also use our CLI tool for automated imports: igetis-keyvault import --file appsettings.json
Security & Compliance
Data protection and certifications
Multi-layer encryption:
- At rest: AES-256 encryption
- In transit: TLS 1.3
- In memory: Encrypted before processing
Key management:
- 🔐 Each customer has unique encryption keys
- 🔐 Keys are rotated automatically every 90 days
- 🔐 Master keys stored in HSM (Hardware Security Module)
- 🔐 Zero-knowledge architecture: we can't read your secrets
Certifications: SOC 2 Type II, ISO 27001, GDPR compliant
Primary data centers:
- 🇬🇧 UK (London) - Default for UK/EU customers
- 🇪🇺 EU (Frankfurt) - Available on request
- 🇺🇸 US (Virginia) - Business Plus and Enterprise only
Data residency:
- Startup & Standard: UK/EU only
- Business Plus: Choose UK, EU, or US
- Enterprise: Custom regions available (contact sales)
Yes, we have:
- ✅ SOC 2 Type II (audited annually)
- ✅ ISO 27001:2013
- ✅ GDPR compliant
- ✅ Data Processing Agreement (DPA) available
Available reports:
- Standard & Startup: Security overview document
- Business Plus: Full SOC 2 report
- Enterprise: Full SOC 2 + ISO + penetration test reports
Contact [email protected] to request reports.
Our incident response process:
- Detection: 24/7 monitoring and alerting
- Containment: Immediate isolation of affected systems
- Notification: Email notification within 24 hours (or 72 hours for GDPR compliance)
- Investigation: Full forensic analysis
- Remediation: Fix vulnerabilities and restore service
- Post-mortem: Transparent report published
IP whitelisting is available on:
- ❌ Startup: Not available
- ✅ Standard: Up to 5 IP addresses
- ✅ Business Plus: Up to 20 IP addresses
- ✅ Enterprise: Unlimited + CIDR ranges
How it works:
- Add allowed IP addresses in dashboard settings
- Enable IP restriction for your project
- Only requests from whitelisted IPs will be allowed
Best practice: Whitelist your production servers' IPs and use VPN IPs for your team's access.
Support & SLA
Getting help when you need it
All plans include support from day one:
| Plan | Channels | Critical Response |
|---|---|---|
| Startup | Email + Portal | 24 hours |
| Standard ⭐ | Email + Tickets | 12 hours |
| Business Plus | Priority Tickets | 4 hours |
| Enterprise | 24/7 Phone + Priority | 1 hour |
Contact methods by plan:
- 📧 Email: [email protected] (all plans)
- 📞 Phone: +32 (0) 491 55 13 45 (Enterprise only, 24/7)
When submitting a ticket, include:
- Your account email
- Project name
- Description of the issue
- Steps to reproduce (if applicable)
- Error messages or screenshots
Support availability:
- Startup & Standard: Monday-Friday, 9am-6pm GMT
- Business Plus: Monday-Friday, 8am-8pm GMT
- Enterprise: 24/7/365 (including weekends and holidays)
We provide service credits:
- Miss response time by >50%: 10% credit
- Miss resolution time by >50%: 25% credit
- Multiple breaches (3+): Up to 100% credit
To claim:
- Email [email protected] with ticket number
- Submit within 30 days of breach
- We'll review and apply credit within 5 business days
We take our SLA commitments seriously and track our performance publicly.
Account Management
Users, teams, and permissions
To invite team members:
- Go to Settings → Team Members
- Click "Invite User"
- Enter their email address
- Assign role (Admin, Developer, Viewer)
- They'll receive an invitation email
Role permissions:
- Admin: Full access, can manage billing and users
- Developer: Can create/edit secrets and projects
- Viewer: Read-only access to secrets
Yes, absolutely! No long-term contracts, no cancellation fees, no hassle.
📝 How to Cancel
- Log in to your dashboard
- Go to Settings → Billing
- Click "Cancel Subscription"
- Select reason (optional, helps us improve)
- Confirm cancellation
📅 What Happens After Cancellation
Immediate effects:
- ✅ Auto-renewal is turned off
- ✅ No future charges
- ✅ Confirmation email sent
- ✅ Cancellation shown in dashboard
Until end of billing period:
- ✅ Full access to all features continues
- ✅ All your data remains accessible
- ✅ Support still available (based on your plan)
- ✅ You can export all data anytime
- ✅ Option to reactivate subscription
After billing period ends:
- ⏸️ Account converts to "read-only" mode for 30 days
- 👀 You can view (but not edit) secrets
- 💾 You can export all data
- 🚫 API access is disabled
- 📧 Reminder emails sent at 7, 14, and 28 days
After 30-day grace period:
- 🗑️ All data is permanently deleted
- ♻️ Cannot be recovered (GDPR compliance)
- 📧 Final notification before deletion
💰 Refunds & Final Billing
Monthly subscriptions:
- No refund for partial month (you keep access until period ends)
- Example: Cancel on Jan 15, paid until Jan 31 → Access until Jan 31
Annual subscriptions:
- Prorated refund available if cancelled within first 60 days
- After 60 days: No refund, but access continues until year-end
- 30-day money-back guarantee applies (full refund)
💡 Alternatives to Cancelling
Consider these options instead:
- Downgrade to Startup: Keep your data for just £19.99/month
- Pause billing: Enterprise plans can pause for up to 3 months/year
- Talk to us: Having issues? We might be able to help!
🔄 Reactivating After Cancellation
- Within 30 days: Reactivate with one click, all data restored
- After 30 days: Start fresh with new account (data cannot be recovered)
- Your previous email can be used for new account
Need help? Contact [email protected] with any questions about cancellation.
Yes! You own your data.
Export formats:
- 📄 JSON (complete data dump)
- 📄 CSV (secrets list)
- 📄 appsettings.json (.NET) / application.yml (Java) / .env (Node.js)
- 📄 .env file (environment variables)
To export:
- Go to your project
- Click "Export" button
- Choose format
- Download file
🔒 Security note: Exports contain unencrypted secrets. Store them securely!
SSO/SAML is available on:
- ❌ Startup: Not available
- ❌ Standard: Not available
- ✅ Business Plus: SAML 2.0 SSO
- ✅ Enterprise: SAML 2.0 + Custom IdP
Supported identity providers:
- ✅ Okta
- ✅ Azure AD / Microsoft Entra
- ✅ Google Workspace
- ✅ OneLogin
- ✅ Auth0
- ✅ Custom SAML 2.0 providers
Setup typically takes 30-60 minutes with our guidance.
Still Have Questions?
Our team is here to help! Get in touch and we'll respond within 4 hours.