Your company's secret-sharing portal — your brand, your SSO
What your team gets
- Your identity provider at the door. Employees sign in with Microsoft Entra ID, Okta, or any OIDC provider — your groups and app roles decide who can send. Disable someone in your directory and their access goes with them.
- Your brand, end to end. Logo, accent color, product name, and footer text — recipients see your company's tool, not ours. Business plans run it on your own domain, like
secrets.yourcompany.com, with TLS handled for you. - Zero-knowledge by construction. Secrets are encrypted in the sender's browser with keys derived from the share code; neither your company nor the platform can read them. Read-once and auto-expiry always on.
- Guest "request a secret" links. Need a credential from a vendor or client? Send them a one-time link — they don't need an account, and what they submit is end-to-end encrypted to you.
- Admin console and usage stats. Branding self-service, per-day send/receive counts, and an emergency switch that signs out every user at once.
- Nothing to host, nothing to patch. Runs on the same hardened multi-tenant platform as the public product, with per-tenant key isolation.
Pricing — flat per organization, not per user
| Team — $49/mo | Business — $99/mo | |
|---|---|---|
| Branded portal (logo, colors, product name) | Yes | Yes |
| Your own SSO (Entra ID, Okta, any OIDC) | Yes | Yes |
| Users | Unlimited | Unlimited |
| Guest request links | Yes | Yes |
| Admin console + usage stats | Yes | Yes |
| Hostname | yourname.shareasecret.io | Your own domain (secrets.yourcompany.com) |
| Support | Standard | Priority |
Pay yearly and get two months free ($490/yr and $990/yr). Every plan starts with a 14-day free trial — no card required. We set up your tenant with you (SSO details and branding), which usually takes under an hour of your IT team's time.
Why not just use the free site?
Please do — shareasecret.io stays free. The business tier exists for the moment a tool becomes policy: you want sending restricted to your staff, a URL your employees recognize and attackers can't imitate with a look-alike, and an audit trail of how much the tool is actually used. That's what SSO gating, custom domains, and the admin console are for.
Common questions
Can you read our secrets? No. Keys are derived from the share code in the sender's browser and never reach the server. We see ciphertext, timing, and counts — nothing else. This is the same protocol as the public product, source on GitHub.
Do recipients need accounts? No. Receiving is always open — the one-time code is the credential. Only sending requires sign-in on your portal.
What about vendors who need to send us credentials? That's the guest request link: your employee generates it signed-in, the outsider uses it once, unauthenticated, end-to-end encrypted.
How do trials work? 14 days, full Business features, no card. Email us, we provision your tenant, you connect your IdP with our step-by-step guide, done.
Start your 14-day trial — no card, set up in under an hour.
Request a trial →