Send sensitive documents, photos and secrets through a protected viewing link. The right person sees it, watermarked with their identity, on your time limit, with every action recorded. And you can pull it back at any moment.
Nothing to sign up for and nothing to type. Six protections, playing out on their own: what your recipient sees, and what comes back to you.
Sent to you separately from the link
The view blurs the moment they click away. It comes back when they return.
Their session blurs within seconds and the link will not open again.
These are real links, not a mock-up. Put your own name in and watch it appear across the page.
A fictional acquisition term sheet with valuations, counterparties and an earn-out schedule. Try to read it: only a small circle under your cursor is ever sharp. Then try to screenshot it.
Passwords, a recovery phrase, a door code and a safe combination. Each line hides on its own and only reveals while you hold it, so one photo of the screen can never catch the set.
Both demos are fictional and safe to open. Unlike a real send, they reset for the next visitor and are not logged. Everything else behaves exactly as it would for your recipient.
A normal attachment is a copy you gave away forever. A SightSealer link is a viewing session you still own.
Upload a document or photos, or type a secret. Pick a protection level: expiry, viewing window, view-once, access code.
Share it by WhatsApp, SMS or email. The recipient opens it in the browser. Nothing to install, no account to make.
Their name and number are watermarked across every page. You see when they opened it, how long they viewed, and every blocked print, copy or capture attempt.
The link expires, burns after one view, or dies the second you press Revoke, even mid-viewing.
Nothing on earth stops a determined person photographing a screen. So every layer here is designed to make what they capture worthless, and attributable.
Viewers state who they are before anything is shown, and accept confidentiality terms. Optional 6-digit access code shared through a separate channel.
The viewer's name and number tiled across every page and baked into the rendered content itself. Any leaked capture names its source.
Only a small area under the finger or cursor is ever sharp. A screenshot, or a photo from a second phone, catches almost nothing.
Set a viewing window with a live countdown, or let the link burn after a single opening.
Download, print, copy and right-click are disabled. The view blurs instantly when the window loses focus. Attempts are recorded.
Freeze a session mid-view, or revoke it outright. Open sessions blur or end within seconds, wherever the viewer is.
Send an upload request and receive a passport, contract or signed page straight into your workspace. No attachment sitting in WhatsApp forever.
Every session is scored on what actually happened: blocked prints, copy attempts, developer tools, recording signals. Honest labels, never fake certainty.
No file is delivered. Content is drawn to the screen and torn down when the session ends. There is no download to forward on.
Verifiable properties, not marketing words. If it is not on this list, we do not claim it.
We tell you exactly what each level can and cannot stop. Security products that promise the impossible are lying to you.
Frictionless. Just a link.
Capture-resistant, not capture-proof: deters and records, and watermarks make leaks traceable.
For material that justifies an install.
Our highest tier: the file never reaches the device.
Draft agreements, settlement figures, client files and advice, with an audit trail of exactly who read what and when.
Off-market packs, owner documents, unit numbers and exclusive pricing, sent to verified buyers only.
Candidate CVs, offers and salary details, without CVs floating around inboxes forever.
Term sheets, valuations and investor material, shown to one named party at a time rather than forwarded round a market.
Offers, payslips, contracts and disciplinary papers, sent to one person, watermarked with their name, gone when you say.
Show a source document to a named person without handing over a file that can be forwarded, cached or leaked onward.
Line-by-line hold-to-reveal secrets that burn after one view. Nothing left in the chat history.
Launch pricing. Early access, subject to change.
Billing is not switched on yet — the Free plan is live and nothing is charged. Choosing Pro or Team registers interest only.
Including the awkward ones. If we dodged these you would be right not to trust us with a contract.
Not from a browser, and no browser-based product can, whatever it claims. What SightSealer does is make capture difficult and make what is captured close to worthless: the reveal strip keeps only a small area sharp, secrets reveal one line at a time, and the view blurs the moment the window loses focus. Every page also carries the viewer's own name and number, so any leaked capture identifies who leaked it. True operating-system screenshot blocking needs an installed app, which is on the roadmap and labelled as not yet available.
Yes, for content. Files and secrets are encrypted in your browser with AES-256-GCM before upload, so our servers hold only ciphertext. The key travels in the part of the link after the #, which browsers never send to a server, so it cannot appear in our logs, our database, or a link preview. Metadata (the title, the recipient's name, the activity log) is not encrypted and is visible to us. We would rather say that plainly than let you assume otherwise.
No. They open the link in any modern browser. Nothing to install, no account to create. They enter their name, which gets watermarked across the view, and an access code if you required one.
Yes. Freeze a session mid-view or revoke it outright, and an open session blurs or ends within about five seconds wherever the viewer is. Links can also expire on a schedule, or burn after a single viewing.
The content is gone, including for us. The key exists only in the link and in the browser that created it. That is the direct consequence of us holding no key, and it is the price of our servers being unable to read your content.
An attachment is a copy you gave away permanently. It can be forwarded, saved and re-shared, and you never find out. A SightSealer link is a viewing session you still control: watermarked with the viewer's identity, time-limited, revocable, and logged.
Browser-based viewing cannot make screenshots impossible. Nobody's can, whatever they claim. What SightSealer does is make capture difficult, make anything captured nearly worthless (blur, reveal strip, one line at a time), and make every view personally attributable through identity capture and watermarks.
End-to-end encryption protects your content from us, from our hosting provider, and from anyone who steals our database. It does not protect you from the person you deliberately showed it to. Those are different problems, and only the first one can be solved with maths.
The limit of browser encryption: we serve the code that holds your key, so you are trusting us not to ship code that leaks it. Every browser-based encrypted service has this property, including the well-known ones. It is reduced by a strict content security policy and by publishing our code. It is never eliminated. An app you install is the stronger answer, and that is the Protected App tier.
Lose the link and the content is gone. Not "contact support" gone. Gone. That is the price of us not holding a key, and we would rather you knew it now than discovered it later.
What revoke can and cannot do: it stops further viewing and stops the link reopening, and a live session blurs within seconds. It cannot reach into a device and erase what a browser already decrypted. Anyone telling you they can claw a document back out of someone's computer is selling you a feeling.
The link is the key. Anyone holding the full link can open it, which is why the access code matters and why you should send it separately.
More honest answers:
Your first protected sends are free. It takes under a minute.
Send something protected