Secretus logo

NIS2 · Secure information sharing

Support your NIS2 security measures.

Give passwords, API keys and sensitive handoffs a defined sharing process. Secretus can help EU organisations apply selected technical measures alongside their internal policies and wider security programme.

How Secretus relates to Article 21

Article 21 calls for proportionate technical, operational and organisational risk-management measures. The mapping below explains our product’s contribution to selected parts of paragraph 2. Read Article 21 on EUR-Lex.

Article 21(2)(h)

Cryptography and encryption

Point (h) covers policies and procedures for cryptography and, where appropriate, encryption.

What Secretus contributes

Standard mode encrypts secrets in your browser using AES-256-GCM. It stores ciphertext temporarily, with the decryption key in the link’s URL fragment. Maximum Security offers browser-to-browser encrypted transfer.

What to account for

Your organisation defines what may be shared, which mode is suitable and how keys and links are handled. Browser encryption depends on trusted devices and application code.

Article 21(2)(i)

Controls around secret access

Point (i) addresses human resources security, access-control policies and asset management.

What Secretus contributes

Standard links allow one successful access, a chosen expiry and revocation before access. Business includes text-only Team Split, using Shamir k-of-n shares for threshold reconstruction.

What to account for

Anyone holding a complete Standard link can open it while valid; verify the recipient and protect the delivery channel. Revocation cannot recall information already read or copied. These features support only part of your access-control practices.

Article 21(2)(j)

Account authentication and secure sharing

Point (j) includes MFA or continuous authentication, secured voice, video and text communications, and secured emergency communication systems within the entity, where appropriate.

What Secretus contributes

Secretus offers authenticator-app MFA for native email/password accounts. It becomes mandatory for paid native accounts after the trial and the five-day setup grace. Google sign-in security factors are managed by Google.

What to account for

Account MFA does not require a Standard-link recipient to authenticate. Encrypted secret sharing can contribute to secure text handoffs; Secretus is not a complete voice, video or emergency communications system.

For organisations across the EU

NIS2 covers defined categories of essential and important entities; it does not automatically apply to every European business. Scope depends on sector, size and specific exceptions. Check the national rules relevant to your organisation and any applicable sector-specific requirements.

European Commission: NIS2 transposition by country

Build the wider process

Define approved recipients and sharing channels, choose an appropriate expiry, and plan credential rotation after suspected exposure. Your NIS2 programme also needs governance, incident handling, continuity, supplier assessment and other applicable measures beyond secret sharing.

References checked: 5 September 2026. Product mapping describes selected capabilities, not a certification or a complete legal assessment.