Secure Share
Share one secret, safely — then let it disappear
Send a single credential or a one-off note with a one-time, password-protected link. It's encrypted in your browser, expires on its own, and we never see what's inside.
What you control
You decide who opens it, and for how long
One-time access
Links are consumed the first time they're opened — no lingering copy to leak later.
Separate password
Each share is locked with its own password, never your account recovery phrase.
Built-in expiry
Every share carries an expiry date, after which the link simply stops working.
Revoke anytime
Revoke a share you've sent and the link is instantly dead, opened or not.
View tracking
See when a share was created, when it expires and how many times it has been opened.
Secrets or messages
Share a full credential — server, username, password, fields and files — or just a secure note.
How it works
The life of a shared secret
From the moment you create a link to the moment it expires — encrypted the whole way.
- 1
Pick what to share
Choose any single credential or write a one-off secure message. You share one item — never your whole vault.
- 2
Set a one-time password
Lock the share with a password chosen just for it — separate from your recovery phrase. A live strength meter helps you pick a strong one.
- 3
Encrypted in your browser
The item is sealed with AES-256-GCM using a key derived from that password. Only ciphertext, a per-share salt and a bcrypt hash of the password ever reach our servers.
- 4
Send the link
You receive a one-time link. Send the link and the password through separate channels for real defense in depth.
- 5
Recipient unlocks locally
They open the link and enter the password; decryption happens entirely in their browser. The password is never transmitted to us.
- 6
It expires on its own
The link is consumed on first open, and every share carries an expiry date. Change your mind? Revoke it and it dies on arrival.
We can't read what you share, either
Zero-knowledge shareThe shared item is encrypted client-side with AES-256-GCM before it leaves the browser. Our servers store only the ciphertext, the per-share salt and a bcrypt hash of the password — never the password or the plaintext. Both password verification and decryption run in the recipient's browser.
What this means for you: A shared link is as zero-knowledge as the rest of your vault: intercepting the link, or breaching our database, still reveals nothing without the password you sent through a separate channel.
Start protecting your credentials today
Set up your encrypted vault in minutes. Your data is encrypted on your device before it ever reaches us — that's a promise backed by math, not policy.