Features

Everything a handover needs, and two things only we do.

Files, QR codes, SSO, an API and a verifiable audit trail are table stakes we match. Encrypted-to-a-person and destroyed-on-ticket-close are why teams switch.

The handover

Request a credential in three clicks.

  • Templates for Windows password, email account, BitLocker key or a custom field set.
  • Short-lived, single-use links with a configurable window and optional challenge code.
  • Held-to-peek reveal with auto-clear, reveal timeout and view limits.
  • Explicit recipients and teams, with an optional org recovery key.
app.safehanded.com/app/requests
A request detail page in SafeHanded: subject, ticket, status, recipients and the lifecycle timeline.
Request detail, subject, recipients, status and timeline.
help.acme-it.example/h/…
The handover page's verify-with-IT panel: named IT contacts to call and confirm the request is genuine before entering anything.
Verify-with-IT, named contacts and a spoken code.
Identity & verification

Prove it's really IT.

  • Passkeys are mandatory for staff, with a WebAuthn step-up on every reveal.
  • A spoken challenge code read out of band, plus an emailed one-time code to the directory address.
  • Active subject verification, a call-back code or verified channel, as org or per-client policy.
Ticketing & delivery

It lives in the ticket.

  • Fully supported adapters for Jira Service Management, Freshservice, Zendesk, ServiceNow, ManageEngine ServiceDesk Plus (Cloud), Zoho Desk and Freshdesk. In preview: HaloPSA, ConnectWise PSA, Syncro, Atera, SuperOps and HubSpot. Anything else connects through the API, or a generic webhook (also in preview).
  • Private notes written back to the ticket, and auto-purge when the ticket closes.
  • Delivery by email, Slack, Teams or SMS, the link only, never the secret.
app.safehanded.com/app/integrations
The integrations page: ticketing, directory, chat and SIEM connectors.
Integrations, ticketing, directory, chat and SIEM.
app.safehanded.com/app/branding
The branding editor: per-client logo, colours, contacts and a live preview of the handover page.
Per-client branding, with a live preview of the real page.
For MSPs & scale

Run it for many clients, as them.

  • Clients with their own branding, custom domains, contacts and directory.
  • Bulk campaigns to request the same credential from many subjects at once.
  • A public API (OpenAPI 3.1) and signed webhooks to wire it into your stack.
IDENTITY

SSO & provisioning

Microsoft Entra and any OpenID Connect provider on every plan, plus SAML and SCIM user and group provisioning with group→role mapping from Team. Google Workspace sign-in and directory sync are coming soon.

AUDIT

Proof for auditors

A log of who handled every password that can't be quietly edited, plus a signed certificate for any handover. See the security model →

RECOVERY

Nothing stranded

Portable keys unlocked by passkey or recovery code, explicit recipients, org recovery key and tested offboarding.

Get started

Everything above is on the free plan's security model.

The crypto, passkeys and audit chain are identical on every tier. Start free and see.

Free plan coming soonSee pricing