What the server sees
Do not take our word for it: check. This demonstration runs Sésame Éclair’s real encryption code in your browser and shows the exact request sent to our servers.
Local demonstration: nothing is actually sent from this page.
What we receive
ciphertextandiv: your secret encrypted with AES-256-GCM, padded to a fixed size to hide its length.id: a random identifier, unrelated to you.manageTokenHash: the fingerprint of your tracking link token, not the token.hasPinand, with a code,pinVerifier: a value derived from the code and the key, useless to us without the key.- The number of reads and the lifetime you chose.
What we never receive
- Your text, files or label in clear.
- The key, placed after the
#sign of the link. Browsers never send that part of the address to servers. - Your PIN or passphrase.
Check it yourself
- Open your browser’s developer tools (F12), Network tab.
- Create a secret from the home page.
- Click the
secretsrequest: its body matches the one shown above.
The limits, honestly
Encryption in a web page assumes the code served by our site is intact. We reduce this risk with a strict security policy (no third-party scripts), verified dependencies, and signed desktop apps and extension that never run remote code. The cryptographic format is published with its test vectors and will be externally audited.