End-to-end encrypted viewing

Share for viewing,
not keeping.

Send sensitive documents, photos and secrets through a protected viewing link. The right person sees it, watermarked with their identity, on your time limit, with every action recorded. And you can pull it back at any moment.

No app for the recipient No account for the recipient Works over WhatsApp
See it work

Every protection, in twenty seconds

Nothing to sign up for and nothing to type. Six protections, playing out on their own: what your recipient sees, and what comes back to you.

SightSealer
00:52 Secured

Enter your access code

Sent to you separately from the link

4
1
7
2
9
3
Unlock
Verified
STRICTLY CONFIDENTIALMERIDIAN CAPITAL
Project Harbour
Prepared for a named recipient. Do not forward.
1. Transaction summary
Indicative terms for the acquisition of the target below. Issued to one named recipient under the confidentiality undertaking accepted on opening.
TargetNorthwind Logistics Ltd
Headline valuationAED 184,500,000
Equity chequeAED 96,000,000
Implied multiple7.4x FY25 EBITDA
2. Consideration
Cash at completionAED 129,150,000
Deferred (24 months)AED 55,350,000
Vendor roll-over12.0%
STRICTLY CONFIDENTIALMERIDIAN CAPITAL
Project Harbour
Prepared for a named recipient. Do not forward.
1. Transaction summary
Indicative terms for the acquisition of the target below. Issued to one named recipient under the confidentiality undertaking accepted on opening.
TargetNorthwind Logistics Ltd
Headline valuationAED 184,500,000
Equity chequeAED 96,000,000
Implied multiple7.4x FY25 EBITDA
2. Consideration
Cash at completionAED 129,150,000
Deferred (24 months)AED 55,350,000
Vendor roll-over12.0%
Sarah Mitchell · +971 50 ••• 4412 Sarah Mitchell · +971 50 ••• 4412 Sarah Mitchell · +971 50 ••• 4412 Sarah Mitchell · +971 50 ••• 4412
Move to reveal. Only a small area shows at once
Portaladmin.northwind.exampleHold
Usernamea.rasheed@northwind.exampleHold
PasswordHv7$qN2-Blackthorn-41Hold
Door code4417#Hold
Safe08-24-19Hold
STRICTLY CONFIDENTIALMERIDIAN CAPITAL
Project Harbour
Prepared for a named recipient. Do not forward.
1. Transaction summary
TargetNorthwind Logistics Ltd
Headline valuationAED 184,500,000
Equity chequeAED 96,000,000
Implied multiple7.4x FY25 EBITDA

Protected content hidden

The view blurs the moment they click away. It comes back when they return.

STRICTLY CONFIDENTIALMERIDIAN CAPITAL
Project Harbour
Prepared for a named recipient. Do not forward.
1. Transaction summary
TargetNorthwind Logistics Ltd
Headline valuationAED 184,500,000
Equity chequeAED 96,000,000
Implied multiple7.4x FY25 EBITDA

Access withdrawn by the sender

Their session blurs within seconds and the link will not open again.

ActivityHigh risk
Opened by Sarah Mitchell · +971 50 ••• 4412
16 Jul at 14:32:04 · 5.30.169.145
Accepted the confidentiality terms
16 Jul at 14:32:06
Content rendered (2 pages)
16 Jul at 14:32:09
Print attempt blocked
16 Jul at 14:33:11
Left the window, view blurred
16 Jul at 14:33:40
No download, print or copy · Identity-watermarked · Activity recorded

Try it for real

Open a live protected link

These are real links, not a mock-up. Put your own name in and watch it appear across the page.

Demo 01 · Confidential document

Project Harbour

A fictional acquisition term sheet with valuations, counterparties and an earn-out schedule. Try to read it: only a small circle under your cursor is ever sharp. Then try to screenshot it.

Reveal strip90s windowWatermarkedNo print
Open the document
Demo 02 · Secret text

Handover credentials

Passwords, a recovery phrase, a door code and a safe combination. Each line hides on its own and only reveals while you hold it, so one photo of the screen can never catch the set.

Hold to revealOne line at a time90s windowNo copy
Open the secret

Both demos are fictional and safe to open. Unlike a real send, they reset for the next visitor and are not logged. Everything else behaves exactly as it would for your recipient.

How it works

Control that survives pressing send

A normal attachment is a copy you gave away forever. A SightSealer link is a viewing session you still own.

1

Protect it

Upload a document or photos, or type a secret. Pick a protection level: expiry, viewing window, view-once, access code.

2

Send one link

Share it by WhatsApp, SMS or email. The recipient opens it in the browser. Nothing to install, no account to make.

3

They view, you see everything

Their name and number are watermarked across every page. You see when they opened it, how long they viewed, and every blocked print, copy or capture attempt.

4

It ends on your terms

The link expires, burns after one view, or dies the second you press Revoke, even mid-viewing.

Protection

Built to make leaking hard, low-value and traceable

Nothing on earth stops a determined person photographing a screen. So every layer here is designed to make what they capture worthless, and attributable.

Identity-bound access

Viewers state who they are before anything is shown, and accept confidentiality terms. Optional 6-digit access code shared through a separate channel.

Moving identity watermark

The viewer's name and number tiled across every page and baked into the rendered content itself. Any leaked capture names its source.

Reveal strip

Only a small area under the finger or cursor is ever sharp. A screenshot, or a photo from a second phone, catches almost nothing.

Timed and view-once

Set a viewing window with a live countdown, or let the link burn after a single opening.

Blocked and blurred

Download, print, copy and right-click are disabled. The view blurs instantly when the window loses focus. Attempts are recorded.

Live control

Freeze a session mid-view, or revoke it outright. Open sessions blur or end within seconds, wherever the viewer is.

Ask, don't just send

Send an upload request and receive a passport, contract or signed page straight into your workspace. No attachment sitting in WhatsApp forever.

Risk-scored sessions

Every session is scored on what actually happened: blocked prints, copy attempts, developer tools, recording signals. Honest labels, never fake certainty.

Nothing left behind

No file is delivered. Content is drawn to the screen and torn down when the session ends. There is no download to forward on.

Under the bonnet

What actually protects it

Verifiable properties, not marketing words. If it is not on this list, we do not claim it.

Security properties
content
AES-256-GCM, encrypted in your browser before it is uploaded. We store ciphertext and nothing else.
the key
Never sent to us. It lives in the part of the link after the #, which browsers do not transmit. It cannot appear in our logs, our database, or a link preview. We could not decrypt your document if we were asked to.
link token
128-bit cryptographically random. Not guessable, not sequential, not tied to your account.
access code
PBKDF2-SHA256, 210,000 iterations, per-link salt. Shown once, never stored in readable form. Five wrong guesses locks the link for 15 minutes.
in transit
TLS on every request, on top of the content encryption.
at rest
Ciphertext in a private bucket, on encrypted storage. No public URL exists, and the contents are unreadable to us regardless.
content delivery
15-minute signed links, minted per session. Nothing permanent for anyone to keep or share.
access control
Row-level database policies. Your sends are readable only by your account, enforced by the database rather than by our code.
viewer isolation
Strict CSP, no framing, no referrer, nothing cached to disk. Every library is served from our own domain, never a public CDN.
trackers
None. No advertising, no analytics, no session recording, no third-party pixels in the viewer.
what we can see
The title, the recipient's name, and the activity log. Not the contents. We say so here rather than let you assume otherwise.
Protection levels

Three tiers, honestly labelled

We tell you exactly what each level can and cannot stop. Security products that promise the impossible are lying to you.

LIVE NOW

Secure Browser View

Frictionless. Just a link.

  • End-to-end encrypted, we cannot read it
  • Identity capture + access codes
  • Moving identity watermark
  • Blur on focus loss, blocked print/copy/download
  • Reveal strip, hold-to-view, countdown, view-once
  • Live freeze and revoke + risk-scored activity log
  • Upload requests for receiving documents

Capture-resistant, not capture-proof: deters and records, and watermarks make leaks traceable.

COMING

Protected App View

For material that justifies an install.

  • True screenshot blocking on Android
  • Screenshot black-out + recording detection on iPhone
  • Device binding and integrity checks
  • Biometric unlock
COMING

Black Room

Our highest tier: the file never reaches the device.

  • Content rendered on our servers
  • Only the visible pixels streamed, encrypted
  • Sender can join and steer the session
  • Session destroyed on exit
Who it's for

Anything that must be seen but shouldn't be kept

Law and professional services

Draft agreements, settlement figures, client files and advice, with an audit trail of exactly who read what and when.

Property

Off-market packs, owner documents, unit numbers and exclusive pricing, sent to verified buyers only.

Recruitment

Candidate CVs, offers and salary details, without CVs floating around inboxes forever.

Deals and finance

Term sheets, valuations and investor material, shown to one named party at a time rather than forwarded round a market.

HR and people

Offers, payslips, contracts and disciplinary papers, sent to one person, watermarked with their name, gone when you say.

Journalism and research

Show a source document to a named person without handing over a file that can be forwarded, cached or leaked onward.

Passwords and codes

Line-by-line hold-to-reveal secrets that burn after one view. Nothing left in the chat history.

Pricing

Free to start. Recipients never pay.

Launch pricing. Early access, subject to change.
Billing is not switched on yet — the Free plan is live and nothing is charged. Choosing Pro or Team registers interest only.

Free

$0
forever · AED 0
  • 5 protected sends a month
  • Documents, photos and secrets
  • Watermark + activity log
  • 24-hour to 7-day expiry
Start free
MOST POPULAR

Pro

$24 / month
for individuals · AED 89
  • 100 protected sends a month
  • View-once, timed windows, reveal strip
  • Access codes + instant revoke
  • Full event timeline per send
  • Larger files
Start free, upgrade in-app

Team

$68 / month
5 seats · under $14 a seat · AED 249
  • Everything in Pro
  • Shared workspace + templates
  • Company branding
  • Central audit trail
Talk to us
Questions

The things people actually ask

Including the awkward ones. If we dodged these you would be right not to trust us with a contract.

Can SightSealer stop someone taking a screenshot?

Not from a browser, and no browser-based product can, whatever it claims. What SightSealer does is make capture difficult and make what is captured close to worthless: the reveal strip keeps only a small area sharp, secrets reveal one line at a time, and the view blurs the moment the window loses focus. Every page also carries the viewer's own name and number, so any leaked capture identifies who leaked it. True operating-system screenshot blocking needs an installed app, which is on the roadmap and labelled as not yet available.

Is SightSealer really end-to-end encrypted?

Yes, for content. Files and secrets are encrypted in your browser with AES-256-GCM before upload, so our servers hold only ciphertext. The key travels in the part of the link after the #, which browsers never send to a server, so it cannot appear in our logs, our database, or a link preview. Metadata (the title, the recipient's name, the activity log) is not encrypted and is visible to us. We would rather say that plainly than let you assume otherwise.

Does the recipient need an app or an account?

No. They open the link in any modern browser. Nothing to install, no account to create. They enter their name, which gets watermarked across the view, and an access code if you required one.

Can I take it back after I have sent it?

Yes. Freeze a session mid-view or revoke it outright, and an open session blurs or ends within about five seconds wherever the viewer is. Links can also expire on a schedule, or burn after a single viewing.

What happens if the link is lost?

The content is gone, including for us. The key exists only in the link and in the browser that created it. That is the direct consequence of us holding no key, and it is the price of our servers being unable to read your content.

How is this different from sending a PDF attachment?

An attachment is a copy you gave away permanently. It can be forwarded, saved and re-shared, and you never find out. A SightSealer link is a viewing session you still control: watermarked with the viewer's identity, time-limited, revocable, and logged.

The honest bit

Browser-based viewing cannot make screenshots impossible. Nobody's can, whatever they claim. What SightSealer does is make capture difficult, make anything captured nearly worthless (blur, reveal strip, one line at a time), and make every view personally attributable through identity capture and watermarks.

End-to-end encryption protects your content from us, from our hosting provider, and from anyone who steals our database. It does not protect you from the person you deliberately showed it to. Those are different problems, and only the first one can be solved with maths.

The limit of browser encryption: we serve the code that holds your key, so you are trusting us not to ship code that leaks it. Every browser-based encrypted service has this property, including the well-known ones. It is reduced by a strict content security policy and by publishing our code. It is never eliminated. An app you install is the stronger answer, and that is the Protected App tier.

Lose the link and the content is gone. Not "contact support" gone. Gone. That is the price of us not holding a key, and we would rather you knew it now than discovered it later.

What revoke can and cannot do: it stops further viewing and stops the link reopening, and a live session blurs within seconds. It cannot reach into a device and erase what a browser already decrypted. Anyone telling you they can claw a document back out of someone's computer is selling you a feeling.

The link is the key. Anyone holding the full link can open it, which is why the access code matters and why you should send it separately.

More honest answers:

Stop sending sensitive things as uncontrolled files

Your first protected sends are free. It takes under a minute.

Send something protected