HOW IT WORKS

Zero-Trust • Edge-Native

📺 Watch Explainer Video

Layer 1: The Vault (Encrypted D1 Database Storage)

Triple-Layer Encryption

All seals are encrypted in the database with multiple security layers:

  • Client-Side Encryption: AES-GCM-256 in your browser before sending
  • Split-Key Architecture: Key A (client) + Key B (server)
  • Server-Side Key Encryption: Key B encrypted with MASTER_ENCRYPTION_KEY
  • Database Storage: Only encrypted blobs stored, never plaintext

Layer 2: The Handshake (Split-Key Crypto)

Trust-Minimized

We use a Split-Key architecture to ensure no single party can decrypt the data early:

  • Key A (User): Stored in the URL hash. Never sent to the server.
  • Key B (Server): Stored in D1 database inside the secure enclave.
  • The Check: The server refuses to release Key B until Now > Unlock_Time.

Layer 3: The Pulse (Dead Man's Switch)

Automated Release

If used as a Dead Man's Switch, the user must click a private "Pulse Link" periodically. If they fail to check in, the seal unlocks automatically for the recipient.

Layer 3.5: Ephemeral Seals (Self-Destructing)

View-Limited Access

Ephemeral seals unlock immediately but auto-delete after a set number of views:

  • Max Views: Configure 1-100 views before deletion
  • Atomic Counting: Race-condition safe view tracking
  • Privacy-Preserving: SHA-256 hashed viewer fingerprints
  • Auto-Deletion: Blob and database cleanup on exhaustion
  • Perfect For: One-time passwords, confidential messages

Layer 4: Auto-Cleanup (Database Protection)

30-Day Retention Policy

To protect database resources, seals are automatically deleted 30 days after unlock:

  • Max Duration: 30 days until unlock
  • Retention: 30 days after unlock
  • Total Lifetime: Maximum 60 days
  • Cleanup: Automated via cron job

Layer 5: Privacy-First Analytics

Zero External Dependencies

Built-in analytics track aggregate metrics without compromising privacy:

  • No Cookies: Zero tracking cookies or session storage
  • No IPs: IP addresses never stored or logged
  • No Personal Data: GDPR compliant by design
  • Aggregate Only: Page views, seal counts, country distribution

Encryption Standards

  • Algorithm: AES-GCM (256-bit)
  • Key Generation: Web Crypto API (CSPRNG)
  • Key Derivation: HKDF for additional security
  • Storage: Cloudflare D1 (Encrypted Blobs + Encrypted Keys)
  • Master Key: Environment secret (never in database)
  • Audit Trail: Immutable access logs

Quick Start Templates

10 Pre-Configured Scenarios

Time-Seal includes ready-to-use templates that auto-configure settings for common use cases:

Ephemeral (Self-Destructing):

  • One-Time Password (1 view)
  • Shared Secret (1 view)

Dead Man's Switch:

  • Crypto Inheritance (30-day pulse)
  • Whistleblower (7-day pulse)
  • Emergency Backup (14-day pulse)

Timed Release:

  • Product Launch (24 hours)
  • Birthday Gift (24 hours)
  • Legal Hold (24 hours)

Progressive Disclosure:

  • Scavenger Hunt (chained clues)
  • Course Content (drip content)

💡 Click any template button on the homepage to auto-fill message placeholders and settings

What Happens After Creation

1. You receive links:

  • Public Vault Link: Share with recipients (contains Key A in URL hash)
  • Pulse Token: Keep secret (only for Dead Man's Switch mode)

2. Save your seal:

  • COPY: Copy vault link to clipboard
  • DOWNLOAD: Save markdown file with all links
  • SAVE: Encrypt and store in browser vault

3. Recipients view the vault:

  • They see a countdown timer (timed seals)
  • Content remains encrypted until unlock time
  • No one can decrypt early—not even you

4. At unlock time:

  • Server releases Key B
  • Browser combines Key A + Key B
  • Content decrypts automatically
  • Ephemeral seals auto-delete after max views