Send a password once.
Then it’s gone.
ShareShield turns a password, key or file into a link that opens once and deletes what it carried. Ask people for credentials the same way, and set the rules for your whole team.
No account needed to send a text secret. New accounts get 14 days of Standard, then move to Free unless you subscribe.
Your secret link is ready
Share this link with the person who needs it.
- Expires
- Sat 4 Oct, 09:41
- Views left
- 10
- Who can open it
- Anyone with the link
01The problem with email
Everyone who can read the password you just emailed
Not just the person you sent it to. The mail admins at both ends. Everyone on CC, BCC and the distribution list. Whoever it’s forwarded to, now or in two years. The shared inbox it landed in. The backups, archives and eDiscovery exports that keep it for years. Every phone and laptop those mailboxes sync to. And whoever breaks into any of them later. Chat has its own version of the same list.
A ShareShield link turns all of that into one person, once, before it expires.
By email
- Subject
- Staging DB login
Hi Sam, here’s the staging login:
db-admin / Tq7!mR2#vK9pLx
- [email protected]the person you meant
- Mail admins at both endsany time
- Everyone on CC and BCCnow
- ops@ distribution listnow
- Whoever it is forwarded tonow or in two years
- The shared inbox it landed inuntil deleted
- Backups, archives, eDiscoveryfor years
- Every synced phone and laptopuntil wiped
- Whoever breaks in laterany time
As a ShareShield link
- [email protected]once, before Sat 4 Oct, 09:41
02The life of a secret
What happens between send and gone.
Each secret is encrypted under its own key the moment you send it. It opens as many times as you allow, once by default. Then the encrypted content is deleted, files included.
09:41:07 sent
You paste it and set the limits
Choose how long the link lives, from an hour to 30 days on Professional, and how many times it can be opened. Add a passcode, or lock it to named recipients.
09:41:09 shared
They get a link, not the password
Paste it into Teams or Slack, or let ShareShield email it. Link previews can’t use up a view: opening the secret takes a deliberate click.
09:52:30 opened
It’s read once, then deleted
The view is taken atomically, so two people can’t both open a one-view link. Anyone who tries later is told it has gone, and to tell you.
Not opened in time? It is deleted at expiry anyway. Sent to the wrong person? Burn it from your dashboard, or give the recipient a burn link so they can destroy it unread.
03Send and request
Hand one over, or ask for one.
Send
Paste it, set its lifetime and views, and share the link. Or email it to up to 10 people, get told when it’s opened, and lock it so only they can: anyone else is asked for a code sent to a recipient’s inbox.
- Text, or files up to 25 MB on paid plans
- A passcode you send another way; five wrong tries destroy it
- Burn it early if plans change
Email the link straight to the people who need it, and optionally make sure only they can open it.
Priya Shah ([email protected]) is asking you for a secret
Available for
1 day3 days7 daysRequest
Need the DNS login from a client, or a contractor’s SSH key? Send a request. They get a one-time form, and what they type comes back to your account as a secret link, not as a reply in a thread you’ll never clean up.
- They don’t need an account
- The request link stays open for up to 7 days
- Your organisation can require them to set a passcode
04For teams
Your rules apply to every link anyone sends.
Organisations get policies the send form can’t argue with, a log of who did what, and sign-in on your terms.
Secret policy
Rules enforced on every secret your organization creates. Limits can only tighten what your plan allows.
- Expiry: up to 3 days (default 1 day)
- Views: up to 3 (default 1)
- Passcode: required
- Viewers: must sign in
- Secret requests: allowed
Policies
Owners set the maximum and default expiry and views, require passcodes, and switch files, requests and anonymous viewers on or off. The send form pre-fills and locks to match, and the API rejects anything outside it.
Audit log
Every secret’s life is recorded, alongside members, API keys, policy, billing, sign-in, 2FA and SSO events. Filter it in the dashboard, or export it as CSV on Professional and Enterprise.
- Overview
- My Secrets
- My Requests
- Team members
- Audit
- Policies
- API keys
- Organization
Audit log
Security-relevant activity across your organization
| Time | Actor | Action | Target | IP |
|---|---|---|---|---|
| 3 Oct, 09:52 | anonymousAnonymous | Secret opened | secret: k7mq2vxr9t | 192.0.2.88 |
| 3 Oct, 09:41 | user[email protected] | Secret emailed to recipients | secret: k7mq2vxr9t | 203.0.113.24 |
| 3 Oct, 09:41 | user[email protected] | Secret created | secret: k7mq2vxr9t | 203.0.113.24 |
| 3 Oct, 09:12 | apiKeyci-deploy | Secret created | secret: 4h2nqz8w0c | 198.51.100.7 |
| 3 Oct, 08:30 | user[email protected] | Member role changed | user: [email protected] | 203.0.113.9 |
| 3 Oct, 08:02 | user[email protected] | Signed in | — | 203.0.113.31 |
Four roles
Owner, admin, member and viewer. Viewers can see what has been shared but cannot create secrets, requests or API keys.
Two-factor authentication
TOTP with any authenticator app, plus backup codes. Require it for the organisation and members are held at enrolment until they set it up.
Single sign-on
Connect your own OIDC identity provider, Microsoft Entra ID first. Verify domains with a DNS record and enforce SSO for everyone on them.
API v2
Create, read and burn secrets from your own tools with API keys that belong to one organisation, carry scopes and can be revoked.
- Every secret is encrypted with AES-256-GCM under its own random data key.
- That key is wrapped by a key-encryption key held on our servers (envelope encryption), and the keys can be rotated.
- The secret’s id is bound in as authenticated data, so ciphertext can’t be moved from one record to another.
- After the last view, a burn or expiry, the encrypted content is deleted, files included. What remains is the record that it existed, for your audit log.
06Who it’s for
For the people who do the handovers.
IT teams and MSPs
Hand a new starter their first password, and collect admin logins from clients, without either sitting in an inbox.
Agencies
Get hosting, DNS and CMS logins from clients through a one-time form instead of a reply-all thread.
Developers
Pass an API key or a .env file to a colleague, or create links from a script with the API.
HR and onboarding
Send day-one credentials that open once, so the welcome email never holds a working password.
Support desks
Ask a customer for a credential mid-ticket without it ending up in the ticket history.
07Pricing
Free to start. Pay when your team needs more.
Prices in US dollars, billed monthly. Every plan gets the same encryption; paid plans add files, more views, longer links and bigger teams.
- Free$0/month
100 secrets a month, up to 5 members, one view per link, 7‑day links, text only.
- Standard$19/month
500 secrets a month, up to 10 members, up to 5 views per link, 7‑day links, files to 1 MB.
- ProfessionalMost popular$49/month
1,000 secrets a month, up to 20 members, up to 10 views per link, 30‑day links, files to 10 MB.
- EnterpriseCustom
Unlimited secrets, unlimited members, up to 100 views per link, 90‑day links, files to 25 MB.
08Guides
How to hand over a credential properly.
Practical, specific and useful whether or not you use ShareShield.
Take the password out of the email.
Send your first secret now, no account needed. Or create an account: 14 days of Standard, then Free, with 100 secrets a month for up to 5 people, unless you subscribe.
