Share a password that self-destructs
Paste a secret, send the link. It is encrypted in your browser and gone after one view — we only ever see ciphertext.
Burns after 1 view · expires in
The secret is encrypted in your browser with the real @shieldfive/crypto core. We store only ciphertext, and it is deleted the moment it is read.
Need to send files, not just text — or collect documents from clients? ShieldFive does end-to-end encrypted storage, sharing and intake, with nothing left in plaintext on our servers.
Get 5 GB freeWhat people share with it
Sending a file rather than a secret? ShieldFive Send encrypts transfers in the browser the same way.
Questions
- How is this zero-knowledge?
- The secret is encrypted in your browser with the open-source @shieldfive/crypto library (XChaCha20-Poly1305). The decryption key is placed in the link after the “#” — a URL fragment, which browsers never send to a server. We receive and store only ciphertext and never the key, so a breach of our servers exposes only ciphertext.
- What does “burns after one view” mean?
- The first time the link is opened, the server returns the ciphertext and immediately deletes it. A second visit finds nothing. One honest caveat: if the network drops after the delete but before the reader receives the response, a one-view secret can be lost — just create and send another.
- Do I need an account?
- No. Anyone can create a secret link for free. Signing in adds link history and higher limits (more views, longer expiry).
- What if I lose the link?
- There is no recovery. The key lives only in the link; if you lose the link — or just the part after the “#” — the secret cannot be decrypted by anyone, including us.