Free, no account, end-to-end encryptedRequest a secret →

Available today

Available

Encrypted in your browser

AES-256-GCM before anything is sent. The key stays in the link, after the #, and never reaches us.

Available

Self-destruction

After 1 to 10 reads, or at the date you choose (5 minutes to 30 days). An expired secret is unreadable at once.

Available

PIN or passphrase

An extra layer, sent through another channel. 5 attempts, then the secret is destroyed.

Available

Read receipt

A private tracking link tells you whether the secret was read, and lets you destroy it first.

Available

Safe from link previewers

Slack, Teams or Outlook may open a link before you do. The secret is only revealed when you click “Reveal”.

Available

Delayed reveal

The secret only opens from a chosen date, for example a new hire's first day.

Available

Encrypted label

The recipient knows what it is before opening: “Website FTP access”. Encrypted too.

Available

Built-in generator

Passwords up to 128 characters, passphrases and PINs, drawn without bias.

Available

Sensitive key detection

Private keys, JWTs, API keys or .env files spotted locally: we suggest a short expiration.

Available

Encrypted files

Up to 100 MB per send, stream-encrypted on your device.

Available

Request a secret

Send a drop link: your client pastes their credentials, encrypted for you alone.

Available

Several recipients

A separate link per person, each with its own read receipt and destruction.

Available

Your own domain, free

Your links on secrets.your-agency.com, with an automatic TLS certificate.

Available

Signed webhooks

Get notified when a secret is read or destroyed. HMAC signature, no content sent.

Available

Network and country rules

Limit opening to the company network or to some countries, checked before any ciphertext is sent.

Available

Drop page in your colours

Your name, colour and logo on the page where clients drop their credentials.

Coming next

Planned

Extension, desktop, mobile, CLI

Share once from a right click, a keyboard shortcut, the share sheet or a terminal.

We cannot read your secrets. Check it.

The key stays in the link

It lives after the # sign, which browsers never send to servers.

Standard encryption

AES-256-GCM and Argon2id through native browser implementations. No home-made cryptography.

Published format

Full specification and public test vectors. External audit planned before 1.0.

Zero trackers

No third-party scripts, no analytics, no ads. Strict security policy.

See what the server receives

Ready to send your first secret?

Free, no account, in under 10 seconds.

Share a secret