Capability

Secure Information

Credentials, numbers, codes: readable once, then deleted. Instead of sitting in an inbox forever.

See all features

Information that takes itself back out of the world.

Readable once, then gone.

The link works exactly one time. After that the information is deleted, even if its validity still has days to run.

The key stays in the link.

Every secret gets its own key. It lives only in the part of the address after the hash sign, which browsers never send to a server.

On the record with the contact.

Sent, opened, revealed: every step is in the contact's timeline with its time and the device used.

A password sent by email is on the road forever

Someone on your team sends a customer their credentials. The message then sits in the customer's inbox, in their reply, in the deleted folder, in the backup, on their phone and in the mail provider's archive. Years later a search still finds it, password in plain text.

The problem is not that your colleague was careless. It is the channel: email is built to keep things, not to forget them.

Secure information turns that around. You leave the information once, the contact retrieves it exactly once, and then it is gone. What remains is the proof that it happened.

How it works

  1. You write the information straight from the contact's record. Credentials, a contract number, a code, up to 10,000 characters.
  2. You choose how long it stays valid. One hour, one day, three days, one week or two weeks.
  3. The contact receives an email in your system's frame: who sent them something, how long the link is valid, and a note not to open it if the message was unexpected.
  4. They open the link and see the information once. After that it is deleted, even if the validity still has time to run.

The key is not in your database

This is what separates the feature from a password field on a form:

  • Every secret gets its own key. Encryption is AES-256-GCM, the same method your browser uses for encrypted connections.
  • The key lives only in the link, in the part after the hash sign. Browsers do not send that part to a server, so it never reaches Caymland M4.
  • Only the encrypted text is stored. Anyone reading the database finds nothing that could be decrypted without the key from the link.
  • Decryption happens in the recipient's browser, not on the server.

Every exchange stays on the record

What is deleted is the information, not its history. In the contact's timeline each exchange is one row that expands:

  • when the information was sent, and by whom,
  • when the recipient opened the page,
  • when they actually revealed the information,
  • with which browser and operating system.

A separate overview lists every exchange with statistics: what is still open, what was retrieved, what expired.

You stay in control

  • Revoke a link at any time, as long as it has not been retrieved.
  • Expiry happens on its own, even if nobody opens it.
  • Deletion follows the first retrieval, with nothing left to do.

The recipient is told plainly on the page that the information will not appear a second time and that they should save it now.

What customers use it for

  • Credentials for a portal, an account or a guest login
  • Contract and policy numbers that should not stay in an inbox
  • One-time codes and activation keys
  • Internal approvals a customer has to confirm once

In every case the same thing holds: the information reaches where it belongs, and nowhere else afterwards.

Questions & answers

Frequently asked questions

01

How long does such a link stay valid?

You choose when you send it: one hour, one day, three days, one week or two weeks. Three days is the default. After that the information can no longer be retrieved, even if it was never opened.

02

Can anyone inside the system read the information?

Not from the database alone. Only the encrypted text is stored; the key is generated per secret and exists only in the link, in the part after the hash sign, which browsers do not send to the server. The decryption happens in the recipient's browser.

03

What happens if the recipient opens the link too late?

They see a note that the information is no longer available and are asked to contact the sender. You simply send it again.

04

What if I made a mistake?

As long as the information has not been retrieved, you revoke the link with one click. It is worthless immediately afterwards.

05

Can I see whether the contact picked it up?

Yes. Every exchange is one row in the contact's history and expands into its steps: when it was sent and by whom, when the page was opened and when the information was actually shown, including browser and operating system. A separate overview lists every exchange with statistics.

06

How long may the information be?

Up to 10,000 characters. That covers credentials, longer keys or a whole block of text.

The difference in one sentence

Other systems send confidential data by email and hope nobody finds it again.Caymland M4 makes sure there is nothing left to find.

See all features