Free, no account, end-to-end encryptedRequest a secret →

The principle

Your secret is encrypted in your browser with a random 256-bit key. That key is placed in the link, after the # sign. Browsers never send that part of the address: our servers only receive an encrypted block they cannot decrypt. Even with full access to our servers and database, nobody can read a secret without the full link.

Anatomy of a link

https://eclair.kayzen-lyon.com/s/35fZoy72KMhzS86v9fUxog#v1.p.8BJ3ft…
  • /s/{id} : Random 128-bit identifier, sent to the server to find the ciphertext.
  • #v1 : Format version.
  • n or p : Without or with a PIN.
  • {key} : 256-bit key. Never sent, never logged.

Cryptographic primitives

UseConstructionImplementation
ContentAES-256-GCM, random 96-bit IV, associated data bound to the secret's identifierWebCrypto
DerivationHKDF-SHA-256, context strings prefixed “eclair v1”WebCrypto
PINArgon2id (64 MiB, 3 passes) then HKDF; HMAC-SHA-256 verifier derived from the link keyhash-wasm
LengthContent padded in tiers (1, 4, 16, 64 KiB…) to hide its real size—

Why the server cannot test your PINs

The verifier sent to the server is computed from the code AND the link key. Without the key, the server can neither check a code nor try one. It only counts failures and destroys the secret on the fifth attempt.

What we protect against

  • A leak of our database or host : It only holds encrypted blocks and a few dates.
  • Link previewers (Slack, Teams, Outlook) : The link page does not contain the secret; it is only delivered after a click, through a POST request.
  • Two simultaneous opens : Read and delete happen in one atomic operation, tested with 100 concurrent reads.
  • Link enumeration : 128 random bits, rate limiting, identical answer for unknown, expired or already-read links.
  • A tampered script : No third-party scripts, strict nonce-based content security policy, pinned and audited dependencies.

The limits, honestly

  • An attacker holding both the link and a copy of our database can test short PINs offline. For a critical secret, choose a passphrase.
  • Encryption in a web page assumes the code served by our site is intact. The signed extension and apps, in preparation, will reduce this risk.
  • We see metadata: dates, size tier, number of reads.
  • A recipient can always copy the secret after reading it.
  • The service has not yet been audited by a third party. The audit is planned before version 1.0 and its report will be published.

Check it yourself

See the request sent to the server

Report a vulnerability

Write to us following our security.txt file. We will never take action against anyone reporting a flaw in good faith. security.txt · contact@kayzen-lyon.fr