Security

Here's exactly what's real, and what isn't.

Most security pages are a list of impressive-sounding claims. We'd rather tell you precisely what actually happens when someone opens a document -- including the limits of what any web-based tool can genuinely do.

Password protection, actually enforced

Not just a prompt on the page -- the document itself won't load without it. Verified server-side, every time.

Email verification

A lighter alternative to a password that also gives you a real identity behind the view, not an anonymous open.

Device-locking

The first device that opens a link is the only one that can. Forwarding the link to someone else simply won't work for them.

Identity-stamped watermarking

Not a generic “Confidential” label -- the actual viewer's identity and timestamp, visibly on the page.

A real, complete access log

Every open, every device, every location -- recorded and visible to whoever sent the document.

Consent-based location

A real browser permission prompt, always skippable, never covert.

Links that actually expire

Set a deadline and the link stops working -- automatically, server-side, not just a countdown for show. Revoke access early at any time.

E-signatures with a real audit trail

Signer identity, IP address, timestamp, and a document hash for tamper-evidence -- recorded on every signed document.

Infrastructure

How your data is actually handled

Encrypted in transit and at rest

Every connection to Revokra runs over TLS. Documents and account data are encrypted at rest in our database provider's infrastructure.

Access is scoped, not shared

Every document, link, and analytics record is tied to the specific organization that owns it. Team members only ever see their own org's data.

Built on infrastructure vetted for this

Authentication, database, and hosting run on established providers built for handling sensitive data at scale -- not custom, unaudited infrastructure.

What we don't claim, and why

No website -- ours or anyone else's -- can actually prevent someone from taking a screenshot. That happens at the operating system level, completely outside of what any browser tab can see or control. If a product claims to be "screenshot-proof," that claim doesn't hold up to a basic technical check.

What we build toward instead is traceability: if something does leak, it's identifiable exactly who had access, from where, and when. Device-locking stops the common case -- someone forwarding a link and it just working for a different person. Identity-stamped watermarking means a screenshot isn't anonymous. A complete access log means nothing happens invisibly.

Read the full breakdown on why this matters →

Questions

Common security questions

Can Revokra actually stop someone from taking a screenshot?

No, and we won't tell you otherwise. Screenshot capture happens at the operating system level, completely outside what any web page can see or control. Any product claiming to be screenshot-proof doesn't hold up to a basic technical check.

What happens if a document does leak?

That's what identity-stamped watermarking and the access log are actually for. A leaked screenshot carries the viewer's identity and timestamp visibly on it, and the access log shows exactly who opened it, from where, and when -- so a leak is traceable, not anonymous.

Can I revoke access to a document after I've sent it?

Yes, at any time, even after it's already been opened. The link simply stops working the moment you deactivate it.

Is my data encrypted?

Yes -- in transit (TLS on every connection) and at rest in our database provider's infrastructure.

Do you sell or share customer data?

No. Your documents and account data are not sold, shared, or used to train anything.

Questions about how this fits your compliance needs?

Start free