About

IT should never ask for a password. It still does.

Every security policy says technicians shouldn't ask for passwords. Then real work gets in the way: a profile rebuild, a mailbox migration, a laptop set up for someone who's away, a cached credential a reset would break. So the password gets sent anyway, over Teams, email or a ticket comment, and it stays there long after the job is done.

SafeHanded exists for those moments.

What happens to a password in SafeHanded

  1. Typed in the user’s browserEncrypted before it leaves their device.
  2. Sealed to one technicianOnly their passkey can open it.
  3. Tied to the ticketEvery step is on record.
  4. Gone when the ticket closesDestroyed automatically, with a note back.

We'd build it so we can't read it. The password is encrypted in the user's browser and sealed to one technician's key. We store ciphertext and hold no key that opens it, so a breach, a rogue insider or a legal order finds nothing readable.

It should disappear when the job does. Each request starts from a helpdesk ticket and is destroyed when that ticket closes, with a note written back and the whole handover on record. Nothing is left behind in an inbox or a chat.

We'd only say what's true. SafeHanded is young, and we'd rather say so than invent customers or badges. We hold no certifications yet; it's built to produce evidence for ISO 27001, Cyber Essentials and SOC 2.

SafeHanded is built and run by Harman AJ Ltd, a company registered in England & Wales (company number 17412886) and the data controller for SafeHanded. Your data is hosted in the European Union.

Contact us →Report a vulnerability →Sub-processors →
Get started

See whether we've earned your trust.

Read the security model, check an audit file yourself, or start on the free plan and put a credential through it.