Secretus logo
BROWSER-SIDE ENCRYPTION · EU OPERATION

Sensitive data deserves ashorter life.

Share passwords, recovery codes and private files without leaving them in chat history. Choose an async one-time link, a live browser-to-browser session, or a threshold split for your team.

Create a protected link
14-day free trialNo credit cardFirefox extension

New protected share

Select the trust boundary

Local encryption

Standard

Async · AES-256-GCM

Maximum Security

LIVE

Live P2P · Hybrid PQ

Team Split

Shamir · k-of-n

The payload stays out of server storage

In Maximum Security mode, the secret travels directly between authenticated browser sessions.

Sender
Recipient

Security posture at a glance

EU operated

Romanian operator · Frankfurt core

Consent controlled

Optional analytics after consent

Authenticated P2P

X3DH-style session setup

Hybrid PQ layer

ML-KEM-768 · NIST FIPS 203

Threshold access

Shamir k-of-n Team Split

Try the real workflow

From sensitive text to a controlled handoff.

Create an account before entering a secret, then choose the trust boundary that matches the job.

Encrypted before upload
Recipient opens without an account
Revoke an unread Standard link

Protected share

Choose a mode, encrypt, share.

01

Select mode

02

Set controls

03

Share safely

Your workspace starts after sign-up

14-day full-access trial. No credit card required.

Encryption happens in your browser; during normal operation, secret endpoints receive ciphertext rather than plaintext.

Security, made usable

Choose the right boundary for every secret.

Secretus does not pretend every transfer has the same threat model. Each mode states where data lives, who must be online and what the recipient needs.

X3DH-style · ML-KEM-768

Hybrid P2P for live transfers

Maximum Security combines authenticated X3DH-style session setup, ML-KEM-768 hybrid key agreement and per-message symmetric ratcheting.

Standard mode

Async one-time links

Send now. Your recipient opens within 15 minutes to 30 days. The AES-256-GCM key stays in the URL fragment.

Short-lived by design

One successful view

The Standard link is invalidated before delivery; ciphertext cleanup follows shortly after with lifecycle deletion as a backstop.

Explicit trust boundaries

Browser-side cryptography

Normal secret requests receive ciphertext, not the URL-fragment decryption key. P2P safety numbers support out-of-band verification.

Shamir k-of-n

Team threshold access

Split a secret into N shares. Any K holders can reconstruct it locally; fewer than K cannot access it alone.

Privacy operations

EU operation & controls

Romanian operation, core account infrastructure in Frankfurt, consent-gated analytics and account export/deletion controls.

Operational control

Confirmation & revocation

See when a secret was opened and revoke an unread Standard link when plans change.

Repeatable workflows

Requests & templates

Ask someone to send you a secret, or start from structured SSH, database, API key and Wi-Fi templates.

A visible trust boundary

Three modes. No hidden trade-offs.

Compare what changes: timing, storage behaviour and how many people must participate.

01

Write Your Secret

Type your secret and choose an expiry — 15 minutes up to 30 days, or a custom date. AES-256-GCM encryption key is generated randomly in your browser.

02

Share the Link

A unique link is generated with the encryption key hidden in the #fragment — invisible to our server. Copy it or share via QR code.

03

Recipient Opens Anytime

The recipient clicks the link whenever they're ready — no scheduling needed. The secret is decrypted locally in their browser.

04

Link Expires

After the first successful view, the link is invalidated immediately and ciphertext cleanup follows shortly after. During normal operation, the key remains in the URL fragment and is omitted from the secret endpoint request.

Built for awkward handoffs

The things that should never live in chat.

A focused workflow for individual sends, live transfers and multi-person recovery.

Passwords & PINs

Credentials and temporary access codes.

Private notes & files

Sensitive text, voice and documents.

Client onboarding

Initial credentials without inbox residue.

Async handoffs

Send now; the recipient opens later.

Team approvals

Require 2-of-3 or 3-of-5 holders.

Recovery material

Controlled delivery of critical codes.

Pricing without procurement theatre

Start small. Change the boundary when needed.

Every plan starts with a 14-day free trial — full access, no credit card required.

Displayed prices exclude applicable VAT, sales tax, or GST. Your final total is shown before checkout confirmation.

14 days free · No credit card · Cancel anytime · Monthly or annual (2 months free)

Starter

Async one-time secret sharing for individuals

€9/per month

14-day free trial included

  • No plan-based monthly secret quota — rate and abuse limits apply
  • Text-only secrets
  • ⚡ Standard Mode — AES-256-GCM (estimated 128-bit security under generic Grover model)
  • Custom expiry: 15 min to 30 days
  • One-time viewing — link invalidated before delivery; cleanup follows
  • Mode-specific backend trust boundary
  • Secret labels & annotations
  • Secret revocation — cancel before opening
  • Delivery confirmation — know when opened
  • 📬 Secret request links — ask others to send you secrets
  • Secret templates — SSH, database, API key, Wi-Fi
  • Audit log — 90-day history, JSON & CSV export
  • Two-factor authentication (TOTP / MFA)
  • Installable PWA — iOS & Android
Recommended

Pro

Add hybrid P2P for high-security transfers

€19/per month

14-day free trial included

  • Everything in Starter
  • 🔒 Maximum Security — X3DH-style + ML-KEM-768 hybrid P2P
  • No secret-payload storage on the server in P2P mode
  • Priority email support — best effort, no SLA

Business

Full suite: files, voice & k-of-n team approval

€33/per month

14-day free trial included

  • Everything in Pro
  • 👥 Teams — share your plan with up to 5 members
  • 🔑 Team Split — Shamir k-of-n threshold
  • Text + file + audio attachments (up to 5 MB)
  • API keys — up to 5 keys, REST API integration
  • 📊 Compliance PDF — evidence for SOC-2, GDPR Art. 30, DORA
  • 1-year audit log retention

Need a custom plan for a larger team? Contact us.

The next credential does not belong in chat.

Put a clear expiry, access boundary and audit trail around the next sensitive handoff.

Review security modes