Share only the records you choose.
Never your account credentials.

Passli lets you generate time-gated, cryptographic Share Passes for sensitive documents—without handing over master logins, permanent drive links, or unencrypted email attachments.

check_circle Client-side AES-256 envelope encryption before upload
check_circle Hardware-enforced expiration & 1-click revocation
check_circle Zero master credential leakage to recipients
Cryptographic key validation and secure document access verification
ACTIVE PASS ENVELOPE
AES-256-GCM

Interactive Share Pass Generator

Experience how client-side cryptographic constraints and real-time key derivation protect your documents.

Create Controlled Share Pass
Define access envelope and file boundary
Token Ready
Select Vault Records 2 selected (3.5 MB)
Cryptographic Expiration Timer
Security Guardrails
Allow In-Browser Decrypted View
Allow Document File Download
Pass Output Artifact LIVE ENCRYPTION
Scan with mobile or reader
Zero payload stored without pass key
Required Access Key
8K7P-42XM
Fingerprint: sha256: 9f8a...3b21
timer Pass validity: 30 mins
Auto-Shredding Server Enforced
Keys generated strictly in client memory. Never transmitted raw.

Built for the moments when privacy matters most

Real-world scenarios where email attachments or full drive shares create permanent security exposures.

Doctor reviewing medical records on tablet
Medical Visits

Clinic & Doctor Consultations

Share blood panels, imaging scans, and prescriptions with a specialist for 30 minutes without exposing insurance numbers, IDs, or financial history.

Professional credential and degree verification
Credentials & KYC

Job Verification & Certifications

Provide temporary authenticated access to diplomas and transcripts during hiring checks without sending unencrypted attachments over email.

Vehicle inspection and registration verification
Vehicle & Legal

Vehicle Registration & Inspections

Present proof of insurance and registration certificates to inspectors via instant QR scan on your phone screen without handing over personal logins.

How Controlled Sharing Operates

A straightforward three-stage architecture keeping you in complete ownership.

STEP 01

Select & Generate

Choose the specific files you want to present from your vault, set expiration (10m - 24h), and generate a Share Pass with a QR code and random Share Key.

STEP 02

Recipient Scans & Authenticates

The recipient scans the QR code to open the isolated access portal, then supplies the 8-character key. The server verifies the cryptographic hash before releasing files.

STEP 03

Automatic Shredding

The recipient views or downloads only authorized files. As soon as the pass expires or is revoked, access is immediately blocked on the server.

Engineered for absolute document sovereignty

Traditional file shares give away account access and permanent links. Passli enforces localized zero-trust boundaries.

shield_lock

Encrypted Vault

Client-side envelope encryption ensures your documents never hit disk unencrypted. Zero knowledge by default across every sector.

Argon2id + AES-256-GCM
fingerprint

Two-Factor Share Access

Require separate Share Key entry before the recipient browser is authorized to decrypt the ephemeral bundle.

Dual-Layer Endpoint Auth
auto_delete

Enforced Expiration

Cryptographic shredding where access keys are permanently erased once the timer lapses or pass is revoked.

Server-side key sanitization
receipt_long

Detailed Access Audit

Immutable server logs pinpointing exact view timestamps, IP geolocation, recipient actions, and validation status.

Verifiable Audit Trail

Institutional Security Comparison

See how Passli’s cryptographic pass structure compares to legacy cloud links and unencrypted email attachments.

Specification
verified Passli Secure Pass
Cloud Storage Folders Email Attachments
Encryption Standard Client-side AES-256-GCM + XChaCha20 Server-side at rest only (Provider master keys) Unencrypted MIME payload in transit
Account Credential Exposure Zero exposure (Ephemeral recipient token) Shared access exposes account / folders Replicated permanently on recipient host
Ephemeral Auto-Shredding Hardware key erasure on timer / 1-view Manual link disabling; persists in cloud Impossible; static copies stored indefinitely
Granular Sub-File Permissions Itemized bundle isolation All-or-nothing folder permission cascades None (Static detached files)
Zero-Knowledge Compliance Mathematically enforced by client proof Cloud employees possess administrative overrides Completely open to SMTP relay inspection

Ready to secure your personal records perimeter?

Launch your vault immediately. Share sensitive files with complete confidence and total control.

lock Launch Personal Vault Sign In