Hybrid P2P for live transfers
Maximum Security combines authenticated X3DH-style session setup, ML-KEM-768 hybrid key agreement and per-message symmetric ratcheting.
Share passwords, recovery codes and private files without leaving them in chat history. Choose an async one-time link, a live browser-to-browser session, or a threshold split for your team.
New protected share
Select the trust boundary
Standard
Async · AES-256-GCM
Maximum Security
LIVELive P2P · Hybrid PQ
Team Split
Shamir · k-of-n
The payload stays out of server storage
In Maximum Security mode, the secret travels directly between authenticated browser sessions.
Security posture at a glance
EU operated
Romanian operator · Frankfurt core
Consent controlled
Optional analytics after consent
Authenticated P2P
X3DH-style session setup
Hybrid PQ layer
ML-KEM-768 · NIST FIPS 203
Threshold access
Shamir k-of-n Team Split
Security, made usable
Secretus does not pretend every transfer has the same threat model. Each mode states where data lives, who must be online and what the recipient needs.
Maximum Security combines authenticated X3DH-style session setup, ML-KEM-768 hybrid key agreement and per-message symmetric ratcheting.
Send now. Your recipient opens within 15 minutes to 30 days. The AES-256-GCM key stays in the URL fragment.
The Standard link is invalidated before delivery; ciphertext cleanup follows shortly after with lifecycle deletion as a backstop.
Normal secret requests receive ciphertext, not the URL-fragment decryption key. P2P safety numbers support out-of-band verification.
Split a secret into N shares. Any K holders can reconstruct it locally; fewer than K cannot access it alone.
Romanian operation, core account infrastructure in Frankfurt, consent-gated analytics and account export/deletion controls.
See when a secret was opened and revoke an unread Standard link when plans change.
Ask someone to send you a secret, or start from structured SSH, database, API key and Wi-Fi templates.
A visible trust boundary
Compare what changes: timing, storage behaviour and how many people must participate.
Type your secret and choose an expiry — 15 minutes up to 30 days, or a custom date. AES-256-GCM encryption key is generated randomly in your browser.
A unique link is generated with the encryption key hidden in the #fragment — invisible to our server. Copy it or share via QR code.
The recipient clicks the link whenever they're ready — no scheduling needed. The secret is decrypted locally in their browser.
After the first successful view, the link is invalidated immediately and ciphertext cleanup follows shortly after. During normal operation, the key remains in the URL fragment and is omitted from the secret endpoint request.
Built for awkward handoffs
A focused workflow for individual sends, live transfers and multi-person recovery.
Credentials and temporary access codes.
Sensitive text, voice and documents.
Initial credentials without inbox residue.
Send now; the recipient opens later.
Require 2-of-3 or 3-of-5 holders.
Controlled delivery of critical codes.
Pricing without procurement theatre
Every plan starts with a 14-day free trial — full access, no credit card required.
Displayed prices exclude applicable VAT, sales tax, or GST. Your final total is shown before checkout confirmation.
Async one-time secret sharing for individuals
14-day free trial included
Add hybrid P2P for high-security transfers
14-day free trial included
Full suite: files, voice & k-of-n team approval
14-day free trial included
Need a custom plan for a larger team? Contact us.
Put a clear expiry, access boundary and audit trail around the next sensitive handoff.