Vault Send Request How it works Security & Trust Pricing 🇬🇧 🇩🇪 🇫🇷
  • Send
  • Request
  • How it works
  • Security & Trust
  • Pricing
  • Vault status

    Operational health, deployed build and cryptography details. No content is exposed.

    The counters below are cumulative totals of encrypted operations. Contents, labels or plaintext are never visible.

    Secrets sent

    264

    Approximate cumulative number of one-time secrets ever created on this instance. A counter that never reveals any content.

    Requests created

    129

    Approximate cumulative number of secret requests ever created on this instance. A counter that never reveals any content.

    Application commit

    9262f6d92

    Short SHA of the deployed monorepo build. This pins the running application code.

    Component commit

    07a857b23

    Short SHA of the last monorepo commit that touched the secrets component. This is what was built.

    Mirror commit

    020115447

    Public mirror commit corresponding to this deployed component. Derived deterministically from the monorepo component tree, so the SHA matches the commit on the mirror. Click to open it.

    Browser JS hash

    b254ee22899155139de11ca98dc2a48b2fb3f3e241448bd9b3429eca6dc3d794

    SHA-256 of the minified secrets bundle delivered to the browser. Fetch the source from the public mirror and recompute the hash to verify what runs in your browser.

    Last deploy

    2026-08-25 18:03:43 UTC

    Modification time of the deployed version file. Cleanup runs once per minute via cron.

    Environment

    production

    All API endpoints are rate-limited per IP to protect the service against abuse.

    License

    AGPL-3.0

    Backend and browser crypto are published under the GNU Affero General Public License v3.0 on the public mirror.

    Cryptography

    All cryptographic operations happen in the browser. The server only ever sees ciphertext.

    Symmetric cipher AES-GCM-256 Key agreement X25519 Key derivation HKDF-SHA256 Password-based derivation PBKDF2-SHA256, 1200000 iterations Nonce 12 bytes random per ciphertext Token 16 bytes random, base64url-encoded Token length 22 characters in the URL path

    Limits

    Values are enforced server-side. Exceeding them returns a 4xx response.

    Lifetime range 60 seconds to 7 days Max ciphertext size 1 MiB per secret Write rate limit per IP 3 requests / 60 seconds Read rate limit per IP 20 requests / 60 seconds

    Source code

    Read each file on the public mirror with syntax highlighting, or grab the raw bytes for offline review and hashing.

    secrets.js (browser crypto) view · raw SecretService.php view · raw SecretsValidators.php view · raw Create.php view · raw Retrieve.php view · raw CreateRequest.php view · raw Fulfill.php view · raw GetRequest.php view · raw RetrieveFulfillment.php view · raw Base64Url.php view · raw SecretLogger.php view · raw
    Share a secret How it works
    Security & Trust Solutions Comparisons Pricing Status Source Privacy Policy DPA Imprint security.txt © 2026 Erseni Ltd. Zero-knowledge by design.