Create an Encrypted Link That Only Your Recipient Can Read
Your content is encrypted in your browser before it ever reaches our servers. Only someone with the link can read it — we cannot.
- AES-256-GCM encryption
- Zero-knowledge architecture
- One-time read
- Optional passphrase
How ProtonURL encryption works
Encryption happens entirely in your browser. Our servers never see your plaintext content.
You enter content
Your secret text or file is processed entirely in your browser.
Browser encrypts
AES-256-GCM encrypts your content using a key generated in your browser.
Only ciphertext stored
We store only the encrypted ciphertext. The decryption key stays in your browser.
Recipient decrypts
The recipient opens the link, decrypts in their browser, reads once, and it's gone.
Enterprise-grade encryption standards
AES-256-GCM
The gold standard in symmetric encryption. Used by governments, banks, and military organizations worldwide. ProtonURL uses AES-256 in GCM mode for authenticated encryption.
PBKDF2 Key Derivation
Keys are derived using PBKDF2 with 310,000 iterations per OWASP recommendations, making brute-force attacks computationally infeasible.
Zero-Knowledge
The decryption key is stored only in the URL fragment (#k=...), which is never sent to our servers. We cannot decrypt your content even if we wanted to.
Authenticated Encryption
GCM mode provides both confidentiality and integrity. Any tampering with the ciphertext is detected and prevents decryption.
Secure Random IVs
Every encryption uses a cryptographically random initialization vector (IV), ensuring identical plaintexts produce different ciphertexts.
File Encryption
Files are encrypted using the same AES-256-GCM standard, chunk by chunk, ensuring the same security for large attachments.
Frequently asked questions
Create your first encrypted link
End-to-end encrypted, zero-knowledge, one-time read. Free, no account required.
Create an encrypted link — free