Authenticated encryption
Secrets are encrypted with AES-256-GCM before being stored. The interface never displays the encryption key.
Openonce is built around one simple idea: sensitive data is safer when it no longer exists. The service limits how long a secret remains available and removes it after opening.
Minimal data, clear behavior, no secret history.
Secrets are encrypted with AES-256-GCM before being stored. The interface never displays the encryption key.
Every secret has an expiration time. Expired encrypted content is removed and the link can no longer reveal it.
After the first successful reveal, the stored ciphertext and IV are set to null so the secret cannot be retrieved again.
Openonce does not require an account and does not build a history of secrets tied to a user profile.
Choose the shortest practical expiration when creating a link.