Password delivery

Content that disappears after it is read.
And proof that it did.

OURPASS delivers a password or a confidential message through a single-use link — and can also have one submitted to you. The content is encrypted, hosted in France, and destroyed as soon as it has been read. Every send leaves a verifiable trace you can hand to an auditor, an insurer or a client.

Start for free See pricing

  • Free plan, no card required
  • Hosted in France
  • GDPR compliant
  1. 1Link generated
  2. 2Sent by SMS or e-mail
  3. 3Viewed once
  4. 4Destroyed

A password sent by email never goes away

You typed it once. It now exists in five places you no longer control:

  • in your Sent folder, for years
  • in the recipient's inbox, and in their backups
  • on their mail provider's servers
  • in a Teams thread nobody cleared when that person left the company

And you know neither who read it, nor when, nor how many times. The day someone asks you to demonstrate it, you will have nothing to show.

Four steps, one minute

Nothing to install — not for you, not for your recipient.

  1. You enter the content

    A password, an API key, a confidential note: you type it into OURPASS. It is encrypted before it even reaches our database. When the other party holds the secret, the direction reverses: you send them a link, and they are the one who submits.

  2. You send the link

    By SMS, by email, or by pasting the link into the tool of your choice. Emails can go out from your own address — it-support@your-company.com — instead of ours: your recipient recognises the sender, and does not wonder whether the message is a scam.

  3. The recipient opens it once

    Once only. You are notified, with the date, the time and the country it was read from. An attempt from a country you did not allow is refused before any decryption, and you are told about it.

  4. The content is destroyed

    It no longer exists anywhere. Reopening the link shows nothing. What remains is proof of the send and of the read — not the content itself.

Three ways to use it

You send a secret, you ask for one, or you do either without leaving the tool you work in. Three situations, one single-use link.

You send

A new employee starts on Monday

A password, an API key, a confidential note. You choose the channel — text message, email, or a link you copy yourself — and you then know who opened it, when and from where.

You request

Your contractor has to give you access

A contractor has to give you an access, a client their hosting password. You send them a submission link: they write on a page that never displays anything back, and you view it once from your account. The content never passes through a mailbox.

Without leaving your page

You have just created an account in your console

You are in your admin tool, you have just created an account. The extension sends the link from there, under the same rules as the site. It reads none of your pages — Chrome says so itself at installation.

Install for Chrome

The sending, not just the link

We send the SMS. And we tell you whether it arrived.

Tools of this kind stop at the link: they hand it to you, and it is up to you to paste it into a message from your own phone, with nothing keeping a record. OURPASS sends it itself, then collects the carrier's delivery receipt — because "sent" means the carrier accepted the message, not that a handset received it.

  • The message leaves from here You type the number, the SMS goes out. Nothing to paste, nothing left sitting in your personal phone, and the send is written to the register like everything else.
  • The receipt, not the promise When the handset has received the message, the carrier confirms it and tracking turns to "delivered", with the time. Until that confirmation arrives, that is stated too — we do not dress a wait up as a success.
  • Failure is told to you Phone off for three days, line cancelled, number blocked: you see it, with the reason the carrier gave. You call the person back instead of waiting for a reading that will never come.
  • Checked before it leaves, and under your name A landline is refused before sending. A recipient who replied STOP is flagged rather than silently ignored. The message fits a single segment — beyond that the carrier bills twice and truncates yours — and it arrives from a named sender, not an unknown number that reads like a scam.

You know what became of every send

A password sent by email vanishes from your sight the second you hit Send. Here, every link keeps its state, and you see it at a glance.

  • Read, or still waiting You can tell what has been opened from what is still pending. An access left open for three days deserves a phone call.
  • When, and from where The date, the time and the country it was opened from. A reading from an unexpected place stands out immediately.
  • Refused attempts An opening from a country you did not allow appears plainly, with its origin. The content itself was never decrypted.
  • Cut it off at any time A link sent to the wrong person is revoked in one click. The content is destroyed on the spot, and the revocation is timestamped.

Each of these events is also written to the proof register, where it becomes something you can produce.

What a self-destructing link does not do

A dozen free tools make a password vanish after reading. None of them lets you demonstrate it.

A register you can produce

Every event — creation, send, reading, geographic refusal, revocation — carries the SHA-256 fingerprint of the one before it. Remove a line, change a date or insert one, and the chain breaks exactly where it was touched. The JSON export carries the whole chain: a third party recomputes it with any tool, without going through us.

Your register, line by line

1
Creationcarriesfirst line, nothing to carryproduces#965ABB25

the same value is carried to the next line

2
Sendcarries#965ABB25produces#8F6E0D58

the same value is carried to the next line

3
Readingcarries#8F6E0D58produces#952925B8

That is the difference between a log and a proof: your history has not been altered, including by us, and it can be checked.

Geographic restriction

Allow opening only from the countries where your recipients actually are — one country, a list, or the European Union in one go. Anywhere else the link is refused before decryption, and you are told of the attempt and where it came from.

Controls that hold

App-based two-factor authentication, which the owner can require across the team. Verification of sign-ins from unknown devices. Adjustable session expiry. Seats managed from the app, without writing to support.

French, end to end

Published by OURTECH, a French company. Hosted in France at OVH. No data outside the European Union, no American subcontractor on the path of what you send.

How it is built, precisely

Enough to answer your IT department without calling us.

Encryption
AES-256-GCM, authenticated. A single byte changed in stored content is rejected: it does not decrypt silently.
The link
A 96-bit token drawn by the server, never by the browser — eighty octillion possible values, for a link that expires and opens only once. It cannot be guessed, nor inferred from earlier ones.
After reading
The content is destroyed in the database. It is not archived, not set aside, not recoverable — by anyone.
Register
A chain of SHA-256 fingerprints, exportable as JSON, verifiable by a third party without our help.
Hosting
OVH, France. Transport encryption enforced, strict security headers, application logs kept outside the web root.
Retention
Eleven automatic purge rules: consumed links, expired links, sign-in tokens, verification codes, dormant accounts. Nothing accumulates without a reason.

Per-user pricing, no commitment

Start for free. Change plan or add seats whenever you like, from inside the app.

Essential

To try the service, no card needed.

Free

no card required

a single user

  • Unlimited e-mail sending (30 per day)
  • 5 free SMS per month
  • Unlimited secure links
  • Access tracking
  • No scheduled or bulk sending
  • Support 8 am – 6 pm on weekdays, reply within 24 to 48 h
Create an account

Most chosen

Professional

For a team sharing credentials every day.

9 € per user, per month

or 90 € per user per year — two months free

from 3 to 10 users

  • Unlimited e-mail sending
  • 50 SMS per user per month, pooled
  • Scheduled sending
  • Access tracking
  • Support 8 am – 9 pm, 7 days a week, reply within 24 h
Choose this plan

Enterprise

For an IT department handling volume.

19 € per user, per month

or 190 € per user per year — two months free

from 3 to 50 users

  • Unlimited e-mail sending
  • 150 SMS per user per month, pooled
  • Bulk sending from a CSV file
  • Scheduled sending
  • Support 8 am – 9 pm, 7 days a week, reply within 24 h
Choose this plan

Prices exclude tax. Included SMS are counted for the whole team, not user by user: five people on the Entreprise plan share 750 SMS a month however they like, with no individual counter blocking whoever sends the most.

What people ask us

What if my recipient never opens the link?

The link expires on the date you set, and the content is destroyed unread. You see it in the tracking view, and you can send a new one. A link left sitting unopened is, incidentally, the first sign that you should check who you sent it to.

What if I revoke a link I have already sent?

The content is destroyed at once. Anyone opening the link afterwards gets a refusal page. The revocation itself is written to the register with a timestamp: you can demonstrate that you cut access, and when.

Can I really put this in front of an auditor?

That is the point. From the proof register you export the whole chain as JSON, along with the verification method. An auditor recomputes the SHA-256 fingerprints with any tool and sees that nothing was altered. A team owner can produce the register for the whole organisation, or only their own.

Do my recipients need an account?

No, and that is deliberate. They receive a link, open it, read the content — or submit their own. Nothing to install, nothing to remember, no data to entrust to us. Only your internal users have an account, and they are the ones you pay for.

How long do you keep my data?

Transmitted content, until it is read or expires — never beyond. Activity records, for as long as the proof requires, then they are purged automatically. The detail is in our privacy policy, and the purge rules run every night.

Can I send to several people at once?

Yes, from a CSV file, on the Entreprise plan: a different password per recipient, one link each, and line-by-line tracking. Twenty recipients per send at most — beyond that, you split the file. This is not a commercial limit: twenty lines can be read over before they go out, and a mistake sent to two hundred people cannot be taken back. Your monthly SMS allowance applies on top.

How do I request a password from someone?

You pick “I am requesting” instead of “I am sending”, and give the recipient as you would for a send. They receive a submission link, write their password, and you are notified — the notice never contains the content, it points you to your tracking page where you display it once. You also see where the submission came from, which lets you tell your contact apart from anyone else.

Can the extension read the sites I visit?

No, and Chrome confirms it at installation: it requests no access to your pages. You type in its own window, it touches nothing else. That is a choice — the version that would read a page selection would require access to all your sites, which we refuse to ask for in a service whose argument is security.

The next password you send

Create an account in a minute and send one. The free plan asks for no card, and you will watch the register fill up from the very first link.

Start for free Install for Chrome