The principle
Your secret is encrypted in your browser with a random 256-bit key. That key is placed in the link, after the # sign. Browsers never send that part of the address: our servers only receive an encrypted block they cannot decrypt. Even with full access to our servers and database, nobody can read a secret without the full link.
Anatomy of a link
https://eclair.kayzen-lyon.com/s/35fZoy72KMhzS86v9fUxog#v1.p.8BJ3ft…/s/{id}: Random 128-bit identifier, sent to the server to find the ciphertext.#v1: Format version.n or p: Without or with a PIN.{key}: 256-bit key. Never sent, never logged.
Cryptographic primitives
| Use | Construction | Implementation |
|---|---|---|
| Content | AES-256-GCM, random 96-bit IV, associated data bound to the secret's identifier | WebCrypto |
| Derivation | HKDF-SHA-256, context strings prefixed “eclair v1” | WebCrypto |
| PIN | Argon2id (64 MiB, 3 passes) then HKDF; HMAC-SHA-256 verifier derived from the link key | hash-wasm |
| Length | Content padded in tiers (1, 4, 16, 64 KiB…) to hide its real size | — |
Why the server cannot test your PINs
The verifier sent to the server is computed from the code AND the link key. Without the key, the server can neither check a code nor try one. It only counts failures and destroys the secret on the fifth attempt.
What we protect against
- A leak of our database or host : It only holds encrypted blocks and a few dates.
- Link previewers (Slack, Teams, Outlook) : The link page does not contain the secret; it is only delivered after a click, through a POST request.
- Two simultaneous opens : Read and delete happen in one atomic operation, tested with 100 concurrent reads.
- Link enumeration : 128 random bits, rate limiting, identical answer for unknown, expired or already-read links.
- A tampered script : No third-party scripts, strict nonce-based content security policy, pinned and audited dependencies.
The limits, honestly
- An attacker holding both the link and a copy of our database can test short PINs offline. For a critical secret, choose a passphrase.
- Encryption in a web page assumes the code served by our site is intact. The signed extension and apps, in preparation, will reduce this risk.
- We see metadata: dates, size tier, number of reads.
- A recipient can always copy the secret after reading it.
- The service has not yet been audited by a third party. The audit is planned before version 1.0 and its report will be published.
Check it yourself
See the request sent to the server
Report a vulnerability
Write to us following our security.txt file. We will never take action against anyone reporting a flaw in good faith. security.txt · contact@kayzen-lyon.fr