Client-side AES-256-GCM
Secrets are encrypted in your browser with a one-time key. VaultLink stores ciphertext and IV, never plaintext.
Securely sharing secrets client side
VaultLink encrypts every secret inside the browser, splits the key from the data, and cleans the vault the moment your instructions are fulfilled.
Secrets are encrypted in your browser with a one-time key. VaultLink stores ciphertext and IV, never plaintext.
Define TTLs and view limits so sensitive payloads evaporate right after their purpose is served.
Send a link, control expiry and views, and give recipients clear status feedback at each step.
Create a VaultLink
Your payload never leaves the browser unprotected. Configure expiration and view limits with confidence.
Workflow
Fast handoff in under 30 seconds with privacy-safe status tracking and no shared passwords in chat histories.
VaultLink encrypts on-device using a fresh key derived from your browser entropy.
We store the ciphertext only. The decryption key stays in your URL fragment for recipients only.
Once the link expires or hits view limits, the payload is purged forever from VaultLink edge storage.
Secure password sharing controls
VaultLink helps teams share passwords and credentials with clear trust boundaries. Ciphertext is stored server-side, while decryption material stays client-side in the URL fragment. One-time links, configurable TTL, and max-view controls support data minimization and access-control policies used in regulated environments.
All data sits in a hardened EU region with encrypted Redis storage and automatic shredding.
Key and IV generation use Web Crypto (`crypto.getRandomValues`) in supported browsers.
Optional, privacy-safe events track create and reveal outcomes with masked paths after consent.
We use one consent cookie and optional analytics storage. Accept enables privacy-safe GA4 metrics with masked paths; reject keeps analytics disabled.