Commit first. Reveal together.
Exchange confidential files without giving either participant an early look, or giving the organizer either private decryption key.
An account is required to organize an exchange. Invited participants enroll through their individual claim links.
Four clear stages. No trust theater.
The exchange boundary is visible from invitation through receipt export, so both participants know what is fixed and when retrieval becomes possible.
- 01
Invite each participant separately
Set the participants, deadline, and file policy. Each person receives a distinct invitation they can revisit through the exchange deadline.
- 02
Create keys in each browser
Each participant enrolls independently. Their browser creates the private key and keeps it out of the organizer’s hands.
- 03
Encrypt, review, and commit
The file and optional access code are encrypted before upload. Once committed, a package cannot be swapped for another.
- 04
Reveal both packages together
Neither side can retrieve early. The second commitment releases both encrypted packages, which are verified and decrypted locally.
The secrets required for the exchange.
- Participant private decryption keys
- Plaintext files
- Packaged passwords or access codes
- Finished participant bearer credentials
The shared state that makes the exchange fair.
- Participant names, email addresses, and public keys
- The selected exchange policy and deadline
- Encrypted packages, integrity hashes, and lifecycle state
- A signed, exportable receipt chain
Use it when sequence matters as much as secrecy.
Private Exchange is designed for two-party, one-package-each workflows. It is not a general collaboration folder, identity-verification service, or recoverable key escrow.
Reciprocal disclosures
Exchange two confidential disclosures without letting one participant inspect the other submission first.
Sealed proposals
Hold both proposals behind the same commitment boundary until each party has deposited its final package.
Protected document swaps
Require a password-protected PDF and carry the access code inside the locally encrypted package.
Time-bounded handoffs
Set an expiration window, track lifecycle state, and export a portable receipt bundle before cleanup.
Set the file boundary before anyone commits.
General exchange
Use broader file types with the same independent enrollment, local encryption, atomic release, and receipt protocol.
Protected PDF
Require a PDF, a password that opens it, and an explicit final commitment confirmation in the participant browser.
Create the exchange. Let the protocol enforce the order.
Invite two participants, choose a policy and deadline, then follow every enrollment, commitment, release, and receipt from one hub.
