Secure credential handover
Encrypted to a person, not a link.
When IT has to be handed a password, SafeHanded encrypts it in the user's browser to the technicians named on the request, ties it to the ticket, and destroys it when the ticket closes.
The problem
Passwords still get handed over. Then they stay.
Profile rebuilds, mailbox migrations, a laptop for someone who's away. The password goes into a chat, an email or a ticket, and nobody ever deletes it.
Step 1 · Sealed in the browser
It's locked before it leaves the user's device.
The browser encrypts the password with AES-256-GCM and seals the key with HPKE to each named technician's key. SafeHanded only ever receives the scrambled result.
Our servers have no decryption API, and an automated test fails the build if secret material could reach the server or its logs.
Step 2 · If the link leaks
A link lets someone submit. Never read.
The link only opens a form that encrypts to Alex's key. Forward it, screenshot it, paste it in the wrong chat: there's still nothing to read.
Add a spoken code that Alex reads out over the phone, and a leaked link can't even open the form.
- Opens the form
- Submits the password
- Reads it back
- Opens the form (without a code)
- Reads anything submitted
- Changes who it's sealed to
Step 3 · Reveal
One touch proves it's Alex, and opens the key.
A fresh passkey touch earns a single-use, 30-second grant. The password is decrypted in Alex's browser, shown, then cleared.
A signed-in session on its own can't reveal anything. Neither can an API key.
Windows password · ticket #48090
Step 4 · The ticket closes
Destroyed when the job is done.
The handover lives and dies with the ticket. When the ticket closes, the job is completed or time runs out, the record is erased and a note goes back to the ticket.
Fully supported: Jira Service Management, Freshservice, Zendesk, ServiceNow, ManageEngine ServiceDesk Plus (Cloud), Zoho Desk and Freshdesk.
Profile rebuild for Jane Doe
The evidence
Proof of who handled every password.
Every step is hash-linked to the one before and signed. Change a single event and the check fails. Auditors can verify an export themselves, in their own browser.
Each handover also gets a chain-of-custody certificate, and the log can stream to your SIEM.
If an account is stolen
A stolen account is not a stolen key.
Signing in opens the account, not a single secret. An attacker can try to set up a new key, but nobody encrypts to it until an established admin approves it and at least 72 hours pass.
Past secrets are never exposed. A sole Owner also needs a code texted to their phone. Opening the old key in that time cancels it.
Fits how you work
Starts in your helpdesk. Ends there too.
Request a password from inside the ticket, get a private note back, and let the ticket's close clean up after you.
Sign in with Microsoft or email and passkeys on every plan. Your own Entra, OpenID Connect or SAML connection, plus SCIM, on Team and MSP.
Fully supported
In preview
For everything else
Pricing
Priced per organisation. Start free.
Each person needs a handover only now and then, so you pay for the organisation, not for every user.
Free
- 2 technicians
- 25 requests, 50 shares a month
- Microsoft or email sign-in
Team
- 5 technicians, then £5
- Unlimited requests
- One helpdesk, your own SSO
MSP
- 10 technicians, then £8
- All helpdesks
- Per-client branding
Prices in GBP, excluding VAT. Auditors are free. 14-day MSP trial, no card. Hosted in the EU.