Secure, ephemeral sharing for teams and their code

Every file and secret sent in Slack
is a future breach.

API keys in chat threads. Passwords in email. Files containing PII or financial data in e-mails. Each one sits there forever — forwarded, screenshotted, leaked. Konfidant replaces them with encrypted, one-time links that self-destruct after the first view — from the dashboard, or straight from your code with our REST API and SDKs.

Shared
Opened once
Gone forever
konfidant.app — Secure Share

File selected

Q4-Financial-Report.pdf

14.2 MB·PDF Document
Ready
Encrypting in your browser…100%
Encrypted on device

One-time encrypted download link — expires in 24h

https://download.konfidant.app/#t=hvs.CAESIOk…&k=…

Q4-Financial-Report.pdf·14.2 MB encrypted·burns on open
AES-256-GCM
encryption standard
Zero
plaintext retention
1×
view per link
4 SDKs
Node · Python · Go · Ruby

The problem your team has right now: API keys sitting in Slack. Database credentials in email threads. PII in Jira tickets. Financial reports in e-mails. None of it expires. All of it can be forwarded, screenshotted, or exfiltrated. Every plaintext secret in a chat thread is a compliance incident — and the breach that triggers it won't warn you first.

How it works

Three steps to zero exposure

01

Encrypt

Paste text or upload a file. It is encrypted with AES-256-GCM on your device — in the browser or in our SDKs — before upload. Plaintext never touches our servers.

02

Share

Get a one-time access link. Send it over Slack, Microsoft Teams, email, or any channel. The link carries no readable data — only a single-use token and the decryption key, kept in the URL fragment that browsers never send to our servers.

03

Gone

The recipient opens it once. The token is consumed, the ciphertext is deleted, and the link is burned. No copies on our servers. No history. No exposure.

Developer API

Create burn-on-read links from your own code

Everything you can share in the dashboard, you can share over a REST API. Encrypt a secret or a file in your backend, CI pipeline, or internal tools and get back a one-time link in a single call. Official SDKs for Node.js, Python, Go, and Ruby encrypt locally — Konfidant only ever receives ciphertext.

# No SDK required — encrypt with KNF1 (see docs), then plain HTTPS + JSON
curl -X POST https://www.konfidant.app/api/v1/texts \
  -H "Authorization: Bearer $KONFIDANT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"ciphertext": "<base64 KNF1 ciphertext>", "ttl_hours": 24}'
201Response
// SDKs append &k=<key> locally to build the share link
{
  "download_url": "https://download.konfidant.app/#t=hvs.CAES...",
  "text_id": "9140b841-2c7e-4f0a-9d1b-6a3e8f2c4d10",
  "expires_at": "2026-10-03T12:00:00Z",
  "verified_burn": true
}

Endpoints

POST/v1/texts

Share client-encrypted text, get a one-time link

POST/v1/files

Get an upload URL for an encrypted file

POST/v1/files/{key}/complete

Finish the upload, get a one-time link

GET/v1/shares

List your organization’s shares

Scoped keys: files:create, texts:create, shares:list
Separate test and live keys, optional expiry
Per-key rate limits up to 240 requests/min
Usage tracked per key, visible in your dashboard

Premium and Enterprise include API access for scripts and CI/CD. Integrating Konfidant into your product? Add an API plan from $29/month.

CI/CD pipelines

Hand deploy credentials to an on-call engineer as a link that burns after one view, instead of printing them in build logs.

Onboarding automation

Send new hires their first passwords and VPN configs from your provisioning scripts. Nothing stays in their inbox.

Inside your product

Deliver API keys, recovery codes, or signed contracts to your own customers. Serve the links from your own domain.

Features

Built for teams that handle sensitive data

Whether you're in legal, infosec, DevOps, or HR — Konfidant gives you the controls to share securely without changing your workflow.

Burn on read

Content is permanently deleted after the first view. The access token is single-use — subsequent requests return 410 Gone.

Unique encryption key per share

A random 256-bit key is generated on your device for every share. It travels only in the link's URL fragment — Konfidant never receives it.

Time-limited access

Set expiry from 1 hour up to 30 days, depending on your plan. Even if the link is never opened, the share expires and the data is deleted.

Hosted in Germany

Our application, database and text storage run in Germany. On paid plans, choose EU or US storage for your files; the Free plan stores files in the US.

Custom domain

Serve share links from your own domain — share.yourcompany.com — with automatic SSL via Cloudflare.

Verified burn & audit logs

For compliance-critical teams: audit logs record who on your team shared what and when. Verified burn records when each share was opened and confirms it was destroyed.

Security architecture

Zero-knowledge by design

Konfidant is architected so that we never hold your plaintext data or your keys. Encryption happens on your device before upload, and the key lives only in the link's URL fragment. Decryption happens in the recipient's browser — and only once. Not even Konfidant can read what you shared.

Client-side AES-256-GCM encryption
Keys never leave the share link
Single-use tokens
Download pages load no third-party scripts
No plaintext logged or retained
Hosted in Germany, EU or US file storage

File selected

Key generated on device

Encrypted on your device

random 256-bit key + AES-256-GCM

Ciphertext uploaded

ciphertext only

Token issued

single-use, expiring

Link ready

#t=token&k=key

Pricing

Simple, transparent pricing

Start free. Scale with your team.

Compare plans

All plans include AES-256-GCM encryption and burn-on-read.

Free

$0

/month

For solo professionals

Get started

Premium

$5

/user/month

For small teams

Start Premium

Enterprise

$250

+ $3/user/mo

For compliance orgs

Start Enterprise

Core Security

Burn on read
AES-256-GCM encryption
Single-use tokens

File & Message Sharing

Message encryption
File encryption
Max file size
5 MB
100 MB
200 MB
Max monthly uploads
50 MB
10 GB
2.5 TB

Access Control

Maximum TTL
8 hours
7 days
30 days

Infrastructure

File storage region
US
EU or US
EU or US
Custom domain + SSL
—

Team & Compliance

Team members
1 user
Up to 20
Unlimited
Audit logs
—
Verified burn
—
—

Developer API & Support

REST API & SDKs
—
API keys
—
5
Unlimited
API shares included / month
—
100
1,000
API add-on for integrations
—
From $29/mo
From $29/mo
Support
Community
Email
Priority, SLA on request

Stop sharing secrets in Slack, Teams, and email.

Set up in 60 seconds. No credit card required. Your next credential goes through Konfidant — not chat.

Create your free account

Building an integration? Read the API docs