Free, no account, end-to-end encryptedRequest a secret →

What the server sees

Do not take our word for it: check. This demonstration runs Sésame Éclair’s real encryption code in your browser and shows the exact request sent to our servers.

Local demonstration: nothing is actually sent from this page.

What we receive

  • ciphertext and iv: your secret encrypted with AES-256-GCM, padded to a fixed size to hide its length.
  • id: a random identifier, unrelated to you.
  • manageTokenHash: the fingerprint of your tracking link token, not the token.
  • hasPin and, with a code, pinVerifier: a value derived from the code and the key, useless to us without the key.
  • The number of reads and the lifetime you chose.

What we never receive

  • Your text, files or label in clear.
  • The key, placed after the # sign of the link. Browsers never send that part of the address to servers.
  • Your PIN or passphrase.

Check it yourself

  1. Open your browser’s developer tools (F12), Network tab.
  2. Create a secret from the home page.
  3. Click the secrets request: its body matches the one shown above.

The limits, honestly

Encryption in a web page assumes the code served by our site is intact. We reduce this risk with a strict security policy (no third-party scripts), verified dependencies, and signed desktop apps and extension that never run remote code. The cryptographic format is published with its test vectors and will be externally audited.