Run your company on a workspace no one else can read.
Notes, chat, calls, mail, calendar, tracker and files for the whole team — sealed end-to-end, even from us. Provision members, share by team, and bring your own email domain. Free for up to 3 people.
- Zero-knowledge
- Free up to 3 seats
- Org email
- On-device AI
Your whole stack, under one key
Stop stitching together seven subscriptions that each read your data. SealedSpace seals them into one encrypted workspace.
Docs & databases, Notion-style
A block editor with 30+ block types, inline databases, live multiplayer cursors and version history — every keystroke encrypted before it leaves your device.
- Databases with table, board, gallery and list views
- Real-time co-editing with per-block comments
- Automatic version snapshots you can time-travel
Channels & DMs without the leak
Slack-style channels, group chats and direct messages living beside your docs — same keys, same zero-knowledge guarantee, same offline-first sync.
- Open channels, private groups and 1:1 DMs
- Encrypted file attachments in any conversation
- Presence and typing indicators in real time
Meetings, not a third-party video cloud
One-to-one encrypted calls and group meetings on our own SFU — screen share, reactions and raise-hand included, never piped through a third-party video cloud.
- Encrypted 1:1 calls straight from any DM
- Group calls with screen sharing on a dedicated SFU
- Rings your other devices, even in the background
Org email on your own domain
A full mailbox inside your workspace — threading, folders and team addresses on a domain you verify yourself. Internal mail is sealed per recipient.
- Bring your domain: DNS-verified, addresses you assign
- Internal mail end-to-end sealed per recipient
- Send and receive external email too
Files the server can’t open
A Drive-style manager for every file your team shares — folders, previews and search, with names and contents encrypted before upload.
- Folder trees with drag-and-drop upload
- Image, video, audio and document previews
- Per-file sharing with folder inheritance
Scheduling the server can’t read
A shared team calendar beside your docs and chat — every event’s title, details and reminders encrypted before they sync.
- Month and agenda views on every device
- Recurring events with invites, RSVPs and reminders
- Event details sealed end to end, even from us
Issues & sprints, Linear-style
Plan and ship with boards, sprints and issues that live next to the docs, chats and files they reference — sealed like everything else.
- Kanban boards with sprint planning and swimlanes
- Issues that link to notes, chat and files
- Titles and comments encrypted end to end
AI that never phones home
Ask questions across your notes, rewrite and summarize, draft email replies — with the model running in your own browser. Not a private cloud: no cloud.
- “Ask your notes” answers grounded in your own content
- Runs in your browser over WebGPU
- Opt-in, and nothing ever leaves your device
Built different, on purpose
Privacy isn’t a feature tier here — it’s the architecture. Everything below falls out of that one decision.
-
On-device AI
Generation runs in your browser over WebGPU. Your prompts, notes and drafts are never someone else’s training data.
-
Works fully offline
Local-first storage means the app is whole without a connection. Changes merge conflict-free when you’re back.
-
Private by default
Notes and files start visible only to you. Share with people, teams or everyone — view or edit, your call.
-
Search that stays home
Full-text search across everything, indexed entirely on your device.
-
Teams & permissions
Group members into teams, share in bulk, and gate admin powers by capability.
-
Leave anytime
One encrypted backup file restores your whole workspace on a fresh device.
The server holds your data, never your keys
Every key is derived and used on your device. What the server stores is mathematically unreadable — here’s the actual chain.
-
Your password + 24 words
Identity starts from a password and a 24-word recovery phrase — or a passkey, so you never hand-keep the phrase.
argon2id(password) → vaultKey -
Keys derived on-device
Signing and encryption keypairs are generated client-side and locked with your vault key before anything is stored.
ed25519 · x25519 · AES-256-GCM -
Sealed per member
Each space key is encrypted to every member individually. Access is cryptographic, not a permission flag.
wrap(spaceKey, member.pubKey) -
Server sees ciphertext
Notes, messages, files, mail — all sealed before upload. A full server breach leaks nothing readable.
9f2c…e81b — opaque bytes
-
Encryption you can’t misconfigure
There is no “enable encryption” toggle to forget — plaintext storage simply doesn’t exist in the system.
-
Passkey recovery
Enroll a passkey and recover your account with your device’s biometrics — the recovery phrase becomes optional to keep on paper.
-
Private version history
Time-travel through encrypted snapshots of any doc with the same zero-knowledge guarantee.
-
Admin without backdoors
Org owners can provision and recover managed members using their own custody key — the host stays blind throughout.
Use it anywhere
SealedSpace runs as a fast web app, installs as a PWA, and ships native desktop apps for macOS, Windows and Linux. Mobile apps are on the way.
-
Web app
Runs in any modern browser — open a tab and you’re working, nothing to install.
-
Install as a PWA
Add it to your dock or home screen in one click; it works offline like a native app.
-
macOS
Native desktop app with the local AI sidecar built in.
-
Windows
Native installer for Windows 10 and 11 (64-bit).
-
Linux
Portable AppImage — no install required. A .deb is on the releases page.
Start free. Pay only as you grow.
Up to 3 people free, forever. Add the rest of the team for $7 a seat (USD; billed in your local currency) through Polar — our merchant of record, so card data never touches our servers and tax is handled for you. Both tiers are the full suite; you only ever pay for seats, never features.
Free
For a founding team finding its feet.
- Up to 3 members, including you
- The full suite: notes, chat, calls, mail, calendar, tracker, Drive
- Org email on your own domain
- Admin provisioning & managed members
- On-device AI for everyone
- Encrypted backup & export
Team
For teams past their first three.
- Everything in Free — the same full suite
- No member cap — add your whole team
- Per-seat billing, monthly or yearly
- Tax handled by Polar (our merchant of record)
- Cancel anytime — members keep full access
For developers
Plan & work from Claude Code
Connect the SealedSpace MCP server and let Claude help you break work down into epics, stories and tasks — then pick an issue and work it, all from your terminal.
npx @sealedspace/mcp link - Discuss requirements, then draft epics → stories → tasks; you review before anything is created.
- Apply the plan to a board, then “work on NUC-42” — Claude reads it, moves it, and marks it done.
- Per-space, opt-in access with a fingerprint check; revoke any time in Settings → Integrations.
Opt-in and under your control. Unlike our on-device AI, content you share with Claude Code is decrypted for the assistant and processed by Anthropic under your own Claude settings — never by us. Everything else stays end-to-end encrypted.
Own your data in four steps
No setup theatre — you’re writing securely in under a minute.
- 01
Create your vault
A password and a 24-word recovery phrase derive your keys on-device. That’s the whole identity setup.
- 02
Work offline or in sync
Write notes and docs that save instantly and locally, then sync seamlessly across your devices.
- 03
Invite your team
Share spaces, channels and files. Keys are wrapped per member, so access is cryptographic — not just a permission flag.
- 04
Keep control
Export a full encrypted backup anytime — your workspace is portable and yours to leave with.
Give your team a sealed space
Everything your company runs on — docs, conversations, meetings, mail, plans and files — in one encrypted workspace you control. Free for your first three people.