Zero-Trust link gateway

Put a firewall in
front of every link
you share.

ShareZT wraps any link or secret in IP rules, geo-fencing, and a password gate. Secrets are encrypted in your browser — the key never reaches us — so nothing is trusted until it's verified, and nothing is readable unless you hold the key.

Free to start · no card required · every request logged.

Live edge log
  • 198.51.100.7 · US-CAALLOW/t/q7Fx2a
  • 45.83.122.9 · RUDROPgeo · region blocked
  • AS14061 · datacenterDROPasn · cloud provider
  • 10.0.4.12 · office vpnALLOWip allowlist
  • 91.207.18.3 · CNDROPpassword · 5 attempts
  • 203.0.113.5 · GBALLOW/t/m3Kp9z · burned
  • 198.51.100.7 · US-CAALLOW/t/q7Fx2a
  • 45.83.122.9 · RUDROPgeo · region blocked
  • AS14061 · datacenterDROPasn · cloud provider
  • 10.0.4.12 · office vpnALLOWip allowlist
  • 91.207.18.3 · CNDROPpassword · 5 attempts
  • 203.0.113.5 · GBALLOW/t/m3Kp9z · burned
The four layers

Four checks between a link and your data.

Stack any combination on a single link. Each one runs server-side, in order, before a single byte is served.

Analytics

See every click

Who opened it, from where, how many times — and which requests got dropped at the gate. The full audit trail for every link you share.

IP ACL

Allow only the right networks

Permit specific addresses or ranges — a corporate VPN, a known office, a single machine. Everything outside the list is dropped before anything loads.

Geo-fence

Fence it to a place

Restrict a link by country, region, or city. Unexpected foreign traffic never reaches the payload — it's turned away at the perimeter.

Identity

Lock it behind a password

A credential gate with automatic lockout after repeated failures. The right IP and the right region still isn't enough — no password, no payload.

Order of operations

Never trust. Always verify. In that order.

Every request to a ShareZT link runs the same pipeline, cheapest checks first. It only resolves if it survives all of them.

01
RATE LIMIT
Throttle floods and brute-force probes per IP.
02
IP ACL
Match the address against allow / block lists.
03
GEO-FENCE
Check country, region, city, and network.
04
IDENTITY
Require the password, if one is set.
05
RELEASE →
All clear — serve the payload, log the hit.

Burn after reading

Open a secret once and its ciphertext is destroyed on the server — deleted, not just flagged. Nothing left to recover.

Webhook alerts soon

Pipe every allow and drop straight to a Discord or Slack channel in real time.

Your own domain pro

Serve links from links.yourbrand.com with automatic certificates.

Zero-knowledge

The gate decides who gets in. The key decides who can read it.

Text secrets are encrypted in your browser with AES-256-GCM. The key rides along in your share link and never touches our servers — so even a total breach of ShareZT can't reveal what you sent. The gate controls who gets the ciphertext; the key controls who can read it; we only ever hold the first. Read how it works →

Share something you actually care about.

Create an account and lock down your first link. Free to start, every request logged from day one.