Keep passwords out of your
email, chat and ticket system.
How it Works
- User enters a Secret, (e.g. a password)
- Secret is AES256 encrypted the by browser sent to the Server.
- Server responds with a URL where the contains access to a One-Time-Secret (OTS).
- The User shares the link with the Recipient
- Recipient follows link and clicks to view the Secret One-Time only!
- Secret is burned! (Deleted from Server)
Security First
- Strong AES 256 Encryption
- Dedicated VPS Hosting on AWS
- Not a phish, recognizable links in your domain.
- All data is encrypted during transit & storage.
- Open Source Software
- All secrets are viewed only once or expire.
- Plain-text only, no file payloads.
- HTTPS TLS/SSL – Qualys “A” Rating
- Compliant with NIST 800-63B section 5.1.1.2 password handling practices when links are shared using a secure channel, e.g. internal email/chat/ticket system.
- HECVAT Security Assessment Response Grade
Want your own?
✓ Hosted using Your Domain.
(Avoid sending suspicious looking links to your users.)
✓ Branded with Your Logo.
✓ Custom Help & Usage Instructions
✓ Custom Secret Expiry Options