Share securely

Info
🔐 Zero-knowledge — encrypted in your browser before upload. I can’t read it either.

Create an encrypted link

Share a file or a secret note via a link that self-destructs on a timer. The contents are encrypted in this browser with a one-time AES-256-GCM key — only ciphertext ever reaches AWS.

📤 Drop a file here, or click to browse

How it works

  1. Your browser generates a one-time AES-256-GCM key and encrypts the file locally — the filename is sealed inside the ciphertext too.
  2. It requests a presigned upload URL from API Gateway → Lambda and uploads only the ciphertext to S3.
  3. The key is appended to the share link as a #fragment — which browsers never send to a server. The recipient’s browser decrypts locally.
  4. Metadata gets a DynamoDB TTL; when it fires, a Stream triggers a reaper Lambda that deletes the object. An S3 lifecycle rule is the backstop.