You send
A new employee starts on Monday
A password, an API key, a confidential note. You choose the channel — text message, email, or a link you copy yourself — and you then know who opened it, when and from where.
Password delivery
OURPASS delivers a password or a confidential message through a single-use link — and can also have one submitted to you. The content is encrypted, hosted in France, and destroyed as soon as it has been read. Every send leaves a verifiable trace you can hand to an auditor, an insurer or a client.
You typed it once. It now exists in five places you no longer control:
And you know neither who read it, nor when, nor how many times. The day someone asks you to demonstrate it, you will have nothing to show.
Nothing to install — not for you, not for your recipient.
A password, an API key, a confidential note: you type it into OURPASS. It is encrypted before it even reaches our database. When the other party holds the secret, the direction reverses: you send them a link, and they are the one who submits.
By SMS, by email, or by pasting the link into the tool of your choice. Emails can go out from your own address — it-support@your-company.com — instead of ours: your recipient recognises the sender, and does not wonder whether the message is a scam.
Once only. You are notified, with the date, the time and the country it was read from. An attempt from a country you did not allow is refused before any decryption, and you are told about it.
It no longer exists anywhere. Reopening the link shows nothing. What remains is proof of the send and of the read — not the content itself.
You send a secret, you ask for one, or you do either without leaving the tool you work in. Three situations, one single-use link.
A new employee starts on Monday
A password, an API key, a confidential note. You choose the channel — text message, email, or a link you copy yourself — and you then know who opened it, when and from where.
Your contractor has to give you access
A contractor has to give you an access, a client their hosting password. You send them a submission link: they write on a page that never displays anything back, and you view it once from your account. The content never passes through a mailbox.
You have just created an account in your console
You are in your admin tool, you have just created an account. The extension sends the link from there, under the same rules as the site. It reads none of your pages — Chrome says so itself at installation.
Install for ChromeThe sending, not just the link
Tools of this kind stop at the link: they hand it to you, and it is up to you to paste it into a message from your own phone, with nothing keeping a record. OURPASS sends it itself, then collects the carrier's delivery receipt — because "sent" means the carrier accepted the message, not that a handset received it.
What you see, on your side
A password sent by email vanishes from your sight the second you hit Send. Here, every link keeps its state, and you see it at a glance.
| Recipient | Sent | State | Place |
|---|---|---|---|
| marie@exemple.fr | 10/08 14:02 | Read | 🇫🇷 |
| 06 12 ** ** 34 | 10/08 11:38 | Pending | — |
| sophie@exemple.fr | 09/08 17:20 | Refused | 🇧🇷 |
| paul@exemple.fr | 09/08 09:05 | Expired | — |
| contact@exemple.fr | 08/08 16:44 | Revoked | — |
Each of these events is also written to the proof register, where it becomes something you can produce.
A dozen free tools make a password vanish after reading. None of them lets you demonstrate it.
Every event — creation, send, reading, geographic refusal, revocation — carries the SHA-256 fingerprint of the one before it. Remove a line, change a date or insert one, and the chain breaks exactly where it was touched. The JSON export carries the whole chain: a third party recomputes it with any tool, without going through us.
Your register, line by line
#965ABB25the same value is carried to the next line
#965ABB25produces#8F6E0D58the same value is carried to the next line
#8F6E0D58produces#952925B8That is the difference between a log and a proof: your history has not been altered, including by us, and it can be checked.
Allow opening only from the countries where your recipients actually are — one country, a list, or the European Union in one go. Anywhere else the link is refused before decryption, and you are told of the attempt and where it came from.
App-based two-factor authentication, which the owner can require across the team. Verification of sign-ins from unknown devices. Adjustable session expiry. Seats managed from the app, without writing to support.
Published by OURTECH, a French company. Hosted in France at OVH. No data outside the European Union, no American subcontractor on the path of what you send.
Enough to answer your IT department without calling us.
Start for free. Change plan or add seats whenever you like, from inside the app.
To try the service, no card needed.
Free
no card required
a single user
Most chosen
For a team sharing credentials every day.
9 € per user, per month
or 90 € per user per year — two months free
from 3 to 10 users
For an IT department handling volume.
19 € per user, per month
or 190 € per user per year — two months free
from 3 to 50 users
Prices exclude tax. Included SMS are counted for the whole team, not user by user: five people on the Entreprise plan share 750 SMS a month however they like, with no individual counter blocking whoever sends the most.
The link expires on the date you set, and the content is destroyed unread. You see it in the tracking view, and you can send a new one. A link left sitting unopened is, incidentally, the first sign that you should check who you sent it to.
The content is destroyed at once. Anyone opening the link afterwards gets a refusal page. The revocation itself is written to the register with a timestamp: you can demonstrate that you cut access, and when.
That is the point. From the proof register you export the whole chain as JSON, along with the verification method. An auditor recomputes the SHA-256 fingerprints with any tool and sees that nothing was altered. A team owner can produce the register for the whole organisation, or only their own.
No, and that is deliberate. They receive a link, open it, read the content — or submit their own. Nothing to install, nothing to remember, no data to entrust to us. Only your internal users have an account, and they are the ones you pay for.
Transmitted content, until it is read or expires — never beyond. Activity records, for as long as the proof requires, then they are purged automatically. The detail is in our privacy policy, and the purge rules run every night.
Yes, from a CSV file, on the Entreprise plan: a different password per recipient, one link each, and line-by-line tracking. Twenty recipients per send at most — beyond that, you split the file. This is not a commercial limit: twenty lines can be read over before they go out, and a mistake sent to two hundred people cannot be taken back. Your monthly SMS allowance applies on top.
You pick “I am requesting” instead of “I am sending”, and give the recipient as you would for a send. They receive a submission link, write their password, and you are notified — the notice never contains the content, it points you to your tracking page where you display it once. You also see where the submission came from, which lets you tell your contact apart from anyone else.
No, and Chrome confirms it at installation: it requests no access to your pages. You type in its own window, it touches nothing else. That is a choice — the version that would read a page selection would require access to all your sites, which we refuse to ask for in a service whose argument is security.
Create an account in a minute and send one. The free plan asks for no card, and you will watch the register fill up from the very first link.