Product comparison
Secretus vs OneTimeSecret
OneTimeSecret is a respected, open-source tool for self-destructing notes, and for casual use it works well. The architectural difference is where encryption happens: with OneTimeSecret, your plaintext travels to their server over TLS and is encrypted there — the operator technically can read secrets during processing (an optional passphrase mitigates this, but the secret still transits at creation).
Secretus encrypts in your browser with the Web Crypto API before upload. Under normal operation, our backend stores ciphertext and does not receive the URL-fragment decryption key. A database or storage-only disclosure therefore exposes ciphertext, not plaintext. Like any web application, this does not protect a compromised device or malicious code delivered before encryption.
Side by side
| Feature | Secretus | OneTimeSecret |
|---|---|---|
| Where encryption happens | In your browser, before upload | On the server (TLS in transit) |
| What does the backend process? | Ciphertext under normal operation | Plaintext during server-side processing |
| One-time self-destructing links | ||
| Live P2P mode — secret not stored server-side | Authenticated X3DH-style + WebRTC | |
| Per-message key rotation in live mode | ||
| Post-quantum key agreement | Hybrid ML-KEM-768 (FIPS 203) | |
| Team k-of-n splitting (Shamir) | ||
| Request a secret from someone | Incoming Secrets is configurable in current self-host docs | |
| Audit log | 90 days Starter/Pro; 1 year Business | Documented as planned |
| Open source / self-hostable | Client code runs unobfuscated; hosted EU | Yes — fully open source |
When OneTimeSecret is the better fit
- • You want to self-host a mature, minimal open-source tool on your own infrastructure.
- • You want basic no-account sending, custom domains, regional hosting choices, or its current Team Plus controls.
When Secretus is the better fit
- • Your security policy requires browser-side encryption so the backend does not receive plaintext during normal operation.
- • You need a mode where the secret is never stored at all (live P2P with per-message key rotation).
- • You share credentials inside a team: Shamir k-of-n split, secret requests, audit trail.
- • You care about harvest-now-decrypt-later: hybrid post-quantum key agreement is built in.
Frequently asked questions
Is OneTimeSecret insecure?
No — for everyday notes it is a solid tool, protected by TLS and encrypted at rest. The difference is the trust model: their server processes your plaintext, so you must trust the operator and their infrastructure. In Secretus Standard mode, browser-side encryption means the backend receives ciphertext rather than plaintext during normal operation. This does not cover compromised endpoints or malicious application code delivered before encryption.
Can Secretus staff or servers read my secrets?
During normal operation, encryption happens in your browser before upload; the URL-fragment decryption key is not sent to the backend. Stored-data compromise therefore exposes ciphertext. This guarantee does not extend to a compromised device, browser extension, or malicious application code delivered before encryption.
Both have one-time links. What's different about delivery?
Secretus uses a conditional claim with a renewable lease, then deletes the one-time database record before returning the payload, so later reads cannot retrieve it. The encrypted S3 object is deleted separately on a best-effort basis and is backstopped by a lifecycle rule. Secretus also offers a live P2P mode in which the secret payload is not stored server-side.
Start a 14-day trial to send; recipients can open one-time links without an account.
Share a secret nowComparison reflects publicly documented behaviour checked on 3 August 2026. Spotted an inaccuracy? Tell us and we'll fix it.
