Share a password that self-destructs

Paste a secret, send the link. It is encrypted in your browser and gone after one view — we only ever see ciphertext.

How the encryption works →

Burns after 1 view · expires in

The secret is encrypted in your browser with the real @shieldfive/crypto core. We store only ciphertext, and it is deleted the moment it is read.

Need to send files, not just text — or collect documents from clients? ShieldFive does end-to-end encrypted storage, sharing and intake, with nothing left in plaintext on our servers.

Get 5 GB free

What people share with it

Sending a file rather than a secret? ShieldFive Send encrypts transfers in the browser the same way.

Questions

How is this zero-knowledge?
The secret is encrypted in your browser with the open-source @shieldfive/crypto library (XChaCha20-Poly1305). The decryption key is placed in the link after the “#” — a URL fragment, which browsers never send to a server. We receive and store only ciphertext and never the key, so a breach of our servers exposes only ciphertext.
What does “burns after one view” mean?
The first time the link is opened, the server returns the ciphertext and immediately deletes it. A second visit finds nothing. One honest caveat: if the network drops after the delete but before the reader receives the response, a one-view secret can be lost — just create and send another.
Do I need an account?
No. Anyone can create a secret link for free. Signing in adds link history and higher limits (more views, longer expiry).
What if I lose the link?
There is no recovery. The key lives only in the link; if you lose the link — or just the part after the “#” — the secret cannot be decrypted by anyone, including us.