Free Tool
Secure Share by Panjiea
Stop emailing passwords. Send a self-destructing link instead.
Why we built it
A client asked us a fair question, and we didn’t have a good answer.
Like most of the industry, we had been handing off credentials using a public secret-sharing site — the kind where you paste a password, get a one-time link, and the link destroys itself once it’s opened. It is a genuinely good pattern, and far better than leaving a password sitting in an inbox forever. The question was simply: who actually runs that domain?
That is exactly the right thing to ask before typing a password into a website. The tool may be excellent and the people behind it entirely honest. But you are trusting a domain you don’t control, an operator you can’t name, and a database you can’t inspect — with a live credential to your own network. “Probably fine” is not a security control.
So we stood up our own
secrets.panjiea.com runs on Panjiea infrastructure, on a Panjiea domain, under Panjiea’s control. It is built on Password Pusher, a well-established open-source project, self-hosted by us rather than rented from a third party. When a client asks who operates it, there is a company name, an address and a phone number attached to the answer.
How it works
- Paste the password, license key, or recovery code you need to hand off.
- Set the lifetime: it expires after a set number of days or a set number of views, whichever comes first. The default is 3 days or a single view.
- Optionally require a passphrase the recipient already knows, so the link alone isn’t enough.
- Optionally add a one-click retrieval step, which keeps link-scanning software in an email gateway from silently burning the view before your recipient gets there.
- Send the link. The sender can also delete it early, the moment it’s no longer needed.
Secrets are encrypted before they are stored and are readable only by whoever holds the link. Once a secret expires, the encrypted record is deleted from the database outright.
Free to use
Secure Share is free, with no account to create — for our clients and for companies that aren’t. Use it for a vendor handoff, a new hire’s first login, a Wi-Fi key for a contractor, or anything else that has no business living in an email thread.
The question that started this is worth asking about every tool your organization trusts with sensitive data. Applying that scrutiny across a network is the work we do.