Secure credential handover

Encrypted to a person, not a link.

When IT has to be handed a password, SafeHanded encrypts it in the user's browser to the technicians named on the request, ties it to the ticket, and destroys it when the ticket closes.

Jane types the password for Acme IT
7f3a c91e 0b44 e8d1 52aa
Sealed to Alex Rivera · 48f5 b7a1 aa3d
Sent to SafeHanded: ciphertext only. We hold no key.

The problem

Passwords still get handed over. Then they stay.

Profile rebuilds, mailbox migrations, a laptop for someone who's away. The password goes into a chat, an email or a ticket, and nobody ever deletes it.

Winter-Fern-2026!
Teams chat
"pw is Winter-Fern-2026!"
Readable by the whole chat and eDiscovery. Deleted: never
Email
Re: laptop set-up
Both mailboxes, forwards and archives. Deleted: never
Ticket comment
#48090, public note
Every agent, and the helpdesk vendor. Deleted: never
Sticky note
on the laptop lid
Anyone who walks past. Deleted: when someone remembers
5 copies · 0 deleted

Step 1 · Sealed in the browser

It's locked before it leaves the user's device.

The browser encrypts the password with AES-256-GCM and seals the key with HPKE to each named technician's key. SafeHanded only ever receives the scrambled result.

Our servers have no decryption API, and an automated test fails the build if secret material could reach the server or its logs.

Winter-Fern-2026!▒▒ 7f3a c91e ▒▒
Jane's browser
Encrypts and seals
SafeHanded
Stores ciphertext
a1f0 93c2 7f3a c91e 0b44 e8d1 52aa 19fe 77c0 3d8b f1a2 6e09 c4b7 0a5f 88d3 21ec
no key here
Alex's browser
Holds the only key
AES-256-GCMHPKE · RFC 9180P-256 identity keys

Step 2 · If the link leaks

A link lets someone submit. Never read.

The link only opens a form that encrypts to Alex's key. Forward it, screenshot it, paste it in the wrong chat: there's still nothing to read.

Add a spoken code that Alex reads out over the phone, and a leaked link can't even open the form.

acme-it.safehanded.com/h/7NbskM…
Jane, who it was for
  • Opens the form
  • Submits the password
  • Reads it back
Someone it was forwarded to
  • Opens the form (without a code)
  • Reads anything submitted
  • Changes who it's sealed to
Readable only with Alex's key. The link even carries a tamper check, kept after the # so it never reaches our server.

Step 3 · Reveal

One touch proves it's Alex, and opens the key.

A fresh passkey touch earns a single-use, 30-second grant. The password is decrypted in Alex's browser, shown, then cleared.

A signed-in session on its own can't reveal anything. Neither can an API key.

Jane Doe
Windows password · ticket #48090
Submitted
Passkey touch
30-second grant
Decrypted here
••••••••••••••••
Shown once, then clearedclears after 60 s

Step 4 · The ticket closes

Destroyed when the job is done.

The handover lives and dies with the ticket. When the ticket closes, the job is completed or time runs out, the record is erased and a note goes back to the ticket.

Fully supported: Jira Service Management, Freshservice, Zendesk, ServiceNow, ManageEngine ServiceDesk Plus (Cloud), Zoho Desk and Freshdesk.

#48090
Profile rebuild for Jane Doe
OpenResolved
Alex Rivera · Sent Jane a secure request
Alex Rivera · Profile rebuilt, closing
SafeHanded · Destroyed because this ticket was closed at 16:42 by Alex Rivera.
Encrypted credentialSealed to Alex Rivera's key
PurgedNothing left to read. The audit trail keeps the record of it.

The evidence

Proof of who handled every password.

Every step is hash-linked to the one before and signed. Change a single event and the check fails. Auditors can verify an export themselves, in their own browser.

Each handover also gets a chain-of-custody certificate, and the log can stream to your SIEM.

Event 41
Request created
hash 9f2c…
Signed ✓
Event 42
Submitted
hash a71e…
Signed ✓
Event 43
Revealed by Alex
hash 3cd0…
Signed ✓
Event 44
Purged
hash e58b…
Signed ✓
Nothing has been changed. Signed with SafeHanded's published key.
This file has been changed at event 43.

If an account is stolen

A stolen account is not a stolen key.

Signing in opens the account, not a single secret. An attacker can try to set up a new key, but nobody encrypts to it until an established admin approves it and at least 72 hours pass.

Past secrets are never exposed. A sole Owner also needs a code texted to their phone. Opening the old key in that time cancels it.

Signs in as Alex
Stolen password and MFA
Tries "start over"
Old secrets stay sealed
New key
Trusted nowhere yet
An admin approvesin the role 7+ days, after checking the fingerprint
AND
72 hours passwith emails and texts to Alex
To Alex: "You started over on SafeHanded."
Cancelled. Old key restored, account locked.

Fits how you work

Starts in your helpdesk. Ends there too.

Request a password from inside the ticket, get a private note back, and let the ticket's close clean up after you.

Sign in with Microsoft or email and passkeys on every plan. Your own Entra, OpenID Connect or SAML connection, plus SCIM, on Team and MSP.

Fully supported

Jira Service ManagementFreshserviceZendeskServiceNowManageEngine ServiceDesk Plus (Cloud)Zoho DeskFreshdesk

In preview

HaloPSAConnectWise PSASyncroAteraSuperOpsHubSpotGeneric webhook

For everything else

Public API (OpenAPI 3.1)Signed webhooks

Pricing

Priced per organisation. Start free.

Each person needs a handover only now and then, so you pay for the organisation, not for every user.

sales@safehanded.com

To get started

Free

£0
  • 2 technicians
  • 25 requests, 50 shares a month
  • Microsoft or email sign-in
For internal IT

Team

£39 /month
  • 5 technicians, then £5
  • Unlimited requests
  • One helpdesk, your own SSO
For MSPs

MSP

£149 /month
  • 10 technicians, then £8
  • All helpdesks
  • Per-client branding

Prices in GBP, excluding VAT. Auditors are free. 14-day MSP trial, no card. Hosted in the EU.

1 / 10