Features
Everything is free, with no account. Items marked “Planned” are not available yet: we only promise what works.
Available today
Available
Encrypted in your browser
AES-256-GCM before anything is sent. The key stays in the link, after the #, and never reaches us.
Available
Self-destruction
After 1 to 10 reads, or at the date you choose (5 minutes to 30 days). An expired secret is unreadable at once.
Available
PIN or passphrase
An extra layer, sent through another channel. 5 attempts, then the secret is destroyed.
Available
Read receipt
A private tracking link tells you whether the secret was read, and lets you destroy it first.
Available
Safe from link previewers
Slack, Teams or Outlook may open a link before you do. The secret is only revealed when you click “Reveal”.
Available
Delayed reveal
The secret only opens from a chosen date, for example a new hire's first day.
Available
Encrypted label
The recipient knows what it is before opening: “Website FTP access”. Encrypted too.
Available
Built-in generator
Passwords up to 128 characters, passphrases and PINs, drawn without bias.
Available
Sensitive key detection
Private keys, JWTs, API keys or .env files spotted locally: we suggest a short expiration.
Available
Encrypted files
Up to 100 MB per send, stream-encrypted on your device.
Available
Request a secret
Send a drop link: your client pastes their credentials, encrypted for you alone.
Available
Several recipients
A separate link per person, each with its own read receipt and destruction.
Available
Your own domain, free
Your links on secrets.your-agency.com, with an automatic TLS certificate.
Available
Signed webhooks
Get notified when a secret is read or destroyed. HMAC signature, no content sent.
Available
Network and country rules
Limit opening to the company network or to some countries, checked before any ciphertext is sent.
Available
Drop page in your colours
Your name, colour and logo on the page where clients drop their credentials.
Coming next
Planned
Extension, desktop, mobile, CLI
Share once from a right click, a keyboard shortcut, the share sheet or a terminal.
We cannot read your secrets. Check it.
The key stays in the link
It lives after the # sign, which browsers never send to servers.
Standard encryption
AES-256-GCM and Argon2id through native browser implementations. No home-made cryptography.
Published format
Full specification and public test vectors. External audit planned before 1.0.
Zero trackers
No third-party scripts, no analytics, no ads. Strict security policy.