HANDOVER
P2P Β· E2EE Β· ZERO RETENTION

Send and receive secrets.Securely.

Handover introduces two browsers to each other and then steps aside. The key is made on your machine, the secret travels straight from their browser to yours, and neither end writes anything down.

Setting up a handover is only available to TelcoEdge staff. If you were sent a link or a key, use the box below.

Paste it here if the link arrived broken. Mail clients wrap long lines and some rewrite them. The key never leaves this browser either way.

What the broker holds

session descriptorstransient
encryption keynever
payloadnever
request or payload logsnone
account recordsno accounts

If we were compelled to hand over everything we hold, it would amount to a few seconds of connection metadata.

Nothing is stored
No ciphertext at rest to subpoena or leak.
The broker is blind
Connection setup only. It never holds the key.
It dies with the tab
Close it and the secret is gone. Nothing to delete.

How Handover works

Handover moves one secret from one browser to another without a server ever holding it. You set one up, send a link, and the two browsers talk to each other. When it is done there is nothing to delete, because nothing was written down.

Nothing is stored on our servers. The whole service is hosted on Cloudflare, with no database, no file storage and no request logging.

Two exceptions, so that claim is exact. Signing in to set up a handover leaves a normal sign-in record, as any staff login does. Sending the optional code by text leaves a message record with the phone carrier, holding the number and the code. Neither touches the secret itself, and neither exists if you send the link without a code.

If you are receiving

  1. Say who you are, what it is about and what you are expecting. All three are shown to the sender so they can see the request is genuine.
  2. Optionally give their mobile. We text them a six digit code, so the link and the code travel by different routes and neither alone is enough.
  3. Click Copy email body. The whole message is written for you, subject line included. Paste it into a new email, add their address and send it from your own mailbox, so it arrives looking like you rather than like a phishing attempt.
  4. Leave the tab open and go and do something else. The transfer completes on its own whenever they connect.
  5. Come back later, copy the secret into your password manager, close the tab.

If you are sending

  1. Open the link you were sent. No account, no sign-up, nothing to install. If the link arrived broken, go to handover.telcoedge.com.au and paste the key into the box on the front page instead.
  2. If they texted you a code, type it and press Connect. The code is part of the key, so nothing can happen until it is in.
  3. Wait for the two browsers to verify each other. If the other tab is closed yours waits until it is back.
  4. Read the panel on the right - who is asking, what it relates to, what they are expecting. It appears only once the channel is verified, so it cannot be faked by whoever sent the link.
  5. Only then does the box for the secret appear. Paste it and press Send.
  6. Close the tab. Your copy is cleared the moment it is away.

What we can and cannot see

the secret itselfnever
who it is from and aboutnever
that a handover happenedyes, plus both IPs and timing

When the two browsers cannot reach each other directly, the encrypted packets are relayed through Cloudflare. They still cannot be read, and each transfer tells you which route it took. Request logging is switched off and there is no database or file storage in the service to write to. Cloudflare still counts traffic at the platform level, as any host does, but that is volume and not content.

If the link arrives broken

Plain-text mail wraps long lines and some gateways rewrite URLs, so an invitation can arrive split across two lines or mangled. If that happens, send them the key on its own - everything after the # - by any channel you like. They go to handover.telcoedge.com.au and paste it into the box on the front page. Nothing about the exchange changes: the key still never leaves their browser.

A short code cannot replace the key. We would have to know it in order to connect the two of you, and something we know is not a secret. The key is long because it is the only thing keeping us out.

What it will carry

Text, up to about 64 KB in one go. That comfortably covers a password, an SSH private key, a PEM certificate or a whole chain, a connection string or a base64 keystore. It is not a file transfer: documents, archives and images are out of scope, and there is no chunking, so anything larger is refused with a message rather than half sent.

What you need

If it does not work

Sleep, a closed tab or a reboot ends it, and a link only ever works once. A handover also expires four hours after it is armed whether anyone turned up or not, and both tabs say so when it happens. In every case nothing is disclosed and nothing is left behind: arm a new handover and send a new link. A missed handover is a missed phone call, and there is deliberately no voicemail.