Security & Trust
Onetime Secret exists to move sensitive information from one person to another without leaving it lying around in inboxes, chat logs, or ticketing systems. This section explains how the service is built to do that safely and where to find the details.
The security model in brief
Section titled “The security model in brief”- One-time access. A secret is designed to be viewed once and then permanently destroyed. Once it has been read (or has expired), it’s gone.
- Encryption in transit and at rest. Secrets are encrypted in transit and at rest across all plans.
- Passphrase protection. You can require a passphrase to view a secret, adding a layer the link alone can’t unlock.
- Time-limited by design. Secrets carry an expiration; choose the shortest practical lifetime to minimize exposure.
- Burn before reading. If a secret hasn’t been viewed yet, you can burn it so it can never be read.
- Data minimization. We aim to collect and retain only what’s necessary — see Data Minimization.
Explore this section
Section titled “Explore this section”- Data Protection — what we store, for how long, where it lives, and how this maps to compliance needs.
- Security Best Practices — practical guidance for sharing secrets safely, including the benefits of Custom Domains.
- Vulnerability Disclosure — how to report a security issue responsibly.
Related
Section titled “Related”- Our Principles — Privacy First, Communication, and Data Minimization.
- Data Center Regions — choose where your data is processed and stored.
- Self-Hosting — run Onetime Secret on your own infrastructure for full control.
Reporting a security issue
Section titled “Reporting a security issue”If you believe you’ve found a vulnerability, please contact our security team at security@onetimesecret.com. See Vulnerability Disclosure for what to include and what to expect.