Who it's for
Confidentiality duties, ordinary staff, no security team
The people below already handle other people's most sensitive documents, and today most of them do it over email. The threat is a breached mailbox, a forwarded thread or a curious administrator — and that is squarely inside what this handles.
Client material that shouldn't sit in a mailbox
Settlement terms, discovery, engagement records. Publish the firm's intake key once and clients send documents in from a browser tab — no portal enrolment, no password reset call, nothing for the client to install.
Stop emailing SSNs
Every January, W-2s and bank details move by email attachment because the alternative is too much friction for the client. Removing the account requirement from the sending side is what actually changes that behaviour.
Wire instructions under dual control
Wire fraud works by producing a convincing document that one person acts on alone. A k-of-n document cannot be opened alone, so a forged instruction fails before anyone has to notice it looks wrong.
Credentials and audit material across client boundaries
Handing over infrastructure documentation without leaving it in a shared drive, and with a disposal term attached at the operator side rather than in a policy document.
Confidential reporting that a mid-size company can actually run
Whistleblower-protection and SOX obligations require a confidential channel. Publishing a verified intake listing gives one that the compliance team can stand behind, without operating specialist infrastructure.
Getting started
Publishing a key takes about a minute
Generate a keypair in your browser, prove the address is yours with a magic link, and your listing becomes discoverable. Anyone can then encrypt to you without an account.