SecretWolf
For MSPs & IT teams

Deliver credentials to clients with proof, not plain email

Managed services run on secrets — admin logins, API keys, VPN configs. SecretWolf hands them over as encrypted, one-time links with recipient verification and the audit trail your clients' security reviews will ask for.

One-time links AES-256-GCM Full audit trail Your brand & domain

Built for how MSPs work

Every admin credential you hand over arrives with the evidence a client's security reviewer asks for: who received it, when, and that it's gone.

Recipient verification

Require a one-time email code before a secret reveals, so an admin password only opens for the person you sent it to.

Audit trail for your security posture

Every handover is logged with timestamps, recipient and view status — the evidence Cyber Essentials assessors and clients expect. Set your own retention.

Encrypted attachments

Send config files, certificates or a VPN profile alongside the secret — scanned for malware, encrypted at rest, and deleted on the same view-or-expiry rules.

Works with Halo PSA, or any stack

Connect Halo PSA and post one-time links and audit updates straight onto a ticket — the note carries the link and the outcome, never the secret. Everything else drives from the API, with signed webhooks when a credential is viewed or a request is fulfilled.

Branded per client

Serve links from your own domain so clients see your MSP, not an unfamiliar tool — reinforcing that you handle their access properly.

One-time and revocable

Links burn on first view or expiry, and you can revoke a secret before it's opened if something changes.

Questions we hear

Does the recipient need to install anything?

No. Clients and technicians open a link in the browser — nothing to install. You can gate it behind an emailed one-time code for sensitive handovers.

Can we integrate it with our PSA or RMM?

Halo PSA has a built-in integration on the Business plan: connect it once and a technician can share a secret from the ticket, with the link and the outcome posted back as a note. For anything else the API creates secrets and requests programmatically, and outbound HMAC-signed webhooks notify your systems on view or fulfilment, so handovers land in your ticketing.

Where is the data hosted?

SecretWolf runs on UK infrastructure over HTTPS end to end, with a strict content-security policy and rate limiting on every public endpoint. Secret payloads are hard-deleted on view or expiry.

Can we prove a credential was delivered?

The audit log records delivery, verification and the single view — metadata only, never the secret — and exports to CSV for client reporting or an audit.

Deliver your next admin credential with proof

Free to start. Recipient verification, attachments and the audit trail arrive on the paid plans.

Start free