Security by reduction

Security

Openonce is built around one simple idea: sensitive data is safer when it no longer exists. The service limits how long a secret remains available and removes it after opening.

Minimal data, clear behavior, no secret history.

Authenticated encryption

Secrets are encrypted with AES-256-GCM before being stored. The interface never displays the encryption key.

Automatic expiration

Every secret has an expiration time. Expired encrypted content is removed and the link can no longer reveal it.

One-time access

After the first successful reveal, the stored ciphertext and IV are set to null so the secret cannot be retrieved again.

No accounts or profiles

Openonce does not require an account and does not build a history of secrets tied to a user profile.

Keep exposure as short as possible

Choose the shortest practical expiration when creating a link.

Create one-time secret