Send it once.
Know who opened it.
Lockeon delivers end-to-end encrypted messages and files that open exactly once — after a password — with every access on a tamper-evident record. A private address like de7dh@lockeon.me stands in for your real inbox — or quietly forwards to it, if you prefer.
A delivery, from seal to record
Write, attach, set the password — Lockeon encrypts everything in your browser and reports back the moment it's opened.
Warsaw, PL · Chrome on macOS
✓ password verified · content destroyed
Three steps. One view. Full proof.
Whether it's a message or a 5 GB file, every delivery follows the same sealed lifecycle.
Encrypted before it leaves your device
Write your message or drop your files. Everything is encrypted in your browser with AES-256-GCM. You set the password — the key is derived from it locally and never transmitted. We store ciphertext we cannot read.
Only a link ever reaches their inbox
Send from your private @lockeon.me address or share the link yourself. The recipient's ordinary inbox receives a secure link — never the content. Include the password, or pass it through a second channel.
Opened once, on the record
The recipient enters the password and views the content exactly once. You get the full record — who, when, where, on what device. Then the ciphertext is destroyed. Permanently.
Mail and files, under the same seal
Both run on the same engine: password-gated, viewable once, fully recorded.
Private mailboxes
Every address is a full mailbox at lockeon.me that reveals nothing about you. Send and receive right in Lockeon — outgoing messages arrive as secure links that open with a password, once.
- Anonymous addresses like
de7dh@lockeon.me, generated in one click - A real inbox — read, reply and manage mail in Lockeon itself
- Optional forwarding — pass incoming mail on to your existing address, sender none the wiser
- Your recipients need no account — just the link and the password
- Burn an address at any time — it stops existing instantly
One-time file drops
Contracts, credentials, medical records, source files — encrypted before upload, downloadable exactly once, with the full chain of custody in your dashboard.
- Up to 5 GB per drop on Professional (100 MB on Personal), encrypted client-side with AES-256
- Single download, enforced server-side — no second chances
- Unopened drops self-destruct on the expiry you set
- Every access attempt logged: time, location, device, result
Built for the hard cases
Sending once is the baseline. Secure requests and scheduled release are part of Professional today. The four controls marked Planned are in development and not available yet.
Collect files, don't just send them
Send a "upload securely here" link instead. Clients, candidates, and counterparties drop files straight into your vault — encrypted on their device, recorded like any delivery.
Know who, for certain
Require an SMS code or a company-domain email check before the password gate. The record then proves not just when it was opened — but by whom.
Screenshots stop being anonymous
View-only documents render in the browser with the recipient's email, IP, and timestamp woven across every page. Copies identify their source.
One send, traceable copies
Deliver to many people at once — each gets their own one-time copy with a unique fingerprint and its own record. If something leaks, you know from whom.
Forwarded links lock themselves
If a link is opened from a second device or location, the delivery freezes and you're alerted instantly. Forwarding becomes evidence, not a breach.
Deliver at the exact right moment
Seal now, release later: embargoed announcements, handovers, contract exchanges. Content stays locked until the date you set — then the one-time rules apply as usual.
Where "probably delivered" isn't good enough
Lockeon is built for work where confidentiality is a professional duty — and proof of access is part of the job.
Legal & advisory
Case files and settlement terms delivered once, with an exportable record for the file.
Finance & deals
Term sheets, payroll and due-diligence files with a chain of custody attached.
HR & recruiting
Offers, references and personal data shared person-to-person, never floating in inboxes.
Healthcare
Results and records that reach one patient, one time — and demonstrably no one else.
Proof, not promises
"Did you get it?" becomes a fact you can point at. Every delivery keeps a tamper-evident record of exactly what happened to it.
-
Every attempt, not just success
Wrong passwords are logged too — with time, location and device. Five failed attempts lock the delivery, destroy its content and alert you by email.
-
Precise to the second
Sealed, sent, verified, opened, destroyed — each event timestamped and ordered, so the sequence itself is evidence.
-
Tamper-evident by design
Records are hash-chained: each entry cryptographically commits to the one before it, so an edited or removed entry breaks the chain visibly. Export the record and re-verify it yourself.
-
Export when it matters
Download any delivery record as PDF or CSV — ready for compliance reviews, disputes, or your own peace of mind.
| 09:14:20 | Sealed | 3 files · 214 MB |
| 09:14:26 | Link sent | via k4x2m@lockeon.me |
| 11:02:47 | Password failed | Berlin, DE · Firefox |
| 11:03:12 | Password verified | Berlin, DE · Firefox |
| 11:03:14 | Downloaded 1/1 | 2 min 41 s transfer |
| 11:05:55 | Destroyed | content unrecoverable |
We can't read it. That's the point.
Lockeon is built zero-knowledge: encryption happens on your device, and the password never travels with the content.
-
Encryption
AES-256-GCM, client-side. Content is sealed in your browser before upload. Our servers only ever store ciphertext — random bytes without the key.
-
Key derivation
Argon2id, on-device. The decryption key is derived from the password on the recipient's device — memory-hard, GPU-resistant. The password is never stored, and it never leaves the sender's device unless they ask Lockeon to text it to the recipient.
-
One-time access
Enforced server-side. The ciphertext is released once, atomically. A second request gets nothing — there is nothing left to get.
-
Audit chain
SHA-256 hash-chained log. Each record entry commits to the previous one. Tampering with an entry breaks the chain visibly.
-
Transport
TLS 1.3 everywhere. Defense in depth: even the ciphertext never travels unencrypted.
One honest caveat: once someone views content, they can screenshot or copy it — no tool can prevent that. What Lockeon guarantees is different: the content can be accessed only once, only with the password, and you will always know exactly when that happened.
{
"ciphertext": "b64:kQ9…Zt2A", // sealed in your browser
"kdf": "argon2id · 64 MiB · t=3",
"views": 1,
"expires_in": "72h",
"max_attempts": 5,
"chain_head": "sha256:9f2c…a41e"
}
// no key · no password · no plaintext
Start free. Stay when it earns it.
Every plan includes zero-knowledge encryption, one-time access, and full delivery records.
Personal
For the occasional sensitive send.
- 5 sealed deliveries per month
- 100 MB per drop
- 1 private address
- 7-day maximum expiry
- Full delivery records, PDF / CSV export
Professional
For people whose work is confidential by default.
- Unlimited sealed deliveries
- 5 GB per drop
- 10 private addresses
- Secure upload requests
- Scheduled release, up to 30-day expiry
- Password by SMS
- Signed record export
Confidential
For inboxes that must stay sealed even from us.
- Everything in Professional
- Encrypted mailbox: mail is sealed to your own key the moment it arrives
- 25 private addresses
- Expiry up to 90 days
- Optional ordinary IMAP mailbox for your mail client
Fair questions
What exactly happens after the recipient views the content?
The encrypted content is deleted from our servers the moment the single permitted view or download completes. What remains is the delivery record — timestamps, access events, device and location metadata — which never contains the content itself.
Can Lockeon read what I send?
No. Content is encrypted in your browser before upload, and the key is derived from a password that never reaches us. We store ciphertext we cannot decrypt. If we were legally compelled to hand over data, there would be nothing readable to hand over. One exception is yours to choose: if you ask us to text the password to the recipient, it passes through Lockeon and our SMS provider on the way, unstored. If we also email the link for that delivery, both halves pass through our systems — share the link yourself to keep them apart.
What if someone enters the wrong password?
Every failed attempt is logged with time, location, and device — and you can see it in the record. After five failed attempts the delivery locks itself, its content is destroyed and you are notified by email, so a brute-force attempt becomes evidence instead of a breach.
What if my recipient loses the content after viewing it?
It's genuinely gone — that's the guarantee, and it cuts both ways. If they need it again, you seal and send a new delivery in seconds. Lockeon never keeps a copy that could be re-shared or leaked later.
Can people send mail to my Lockeon address?
Yes — every address is a real, two-way mailbox. Anything sent to de7dh@lockeon.me lands in your Lockeon inbox, where you can read it and reply. Mail arriving from outside comes over ordinary email, so unlike sealed deliveries it is not end-to-end encrypted. On the Confidential plan the mailbox is sealed to your own key the moment mail arrives: our server sees a message only in that instant, and afterwards only you can open it. An ordinary IMAP mailbox, if you turn it on, is not encrypted. If you prefer to stay in your usual client, switch on forwarding and incoming mail is passed to your existing address — the sender never learns it. Burn the address when it has served its purpose.
How is this different from a "secret note" site?
Three ways: a password gate on every delivery, not just an obscure link; a tamper-evident access record you can export as evidence; and private relay mail, so whole conversations — not just one-off notes — can run through sealed, one-time deliveries.
How long do you keep my data?
Ciphertext is deleted the moment the single view completes, when the delivery expires, or when five wrong passwords lock it — whichever comes first. What remains is the delivery record: timestamps, access events, device and network metadata, never the content. You can delete a record, or your whole account, at any time.
Some things should only be seen once.
Seal your first delivery in under a minute. No card required.