Protected inquiry
Send a protected inquiry.
Your note and reply details are encrypted in this browser before delivery, then opened locally by Spanwork.
Channel at a glance
- You provide
- A reply route and short context
- The site delivers
- An encrypted package, not readable fields
- Spanwork opens
- On an authorized device, then contacts you as requested
Your IP address and request timing remain visible to hosting infrastructure.
How protected intake works
The website handles one encrypted delivery. It does not create a live or anonymous messaging account.
-
Protected before upload
The form uses Spanwork's public key to turn your answers into ciphertext before the request leaves this page.
-
Encrypted package delivered
The intake endpoint and mailbox receive the encrypted package. They do not receive your note or reply details as readable text through this flow.
-
Opened away from the site
Spanwork transfers the package to an authorized local device and opens it with the matching private key. The key is not stored on the website, Worker, or mailbox.
Share only enough to make contact.
This is a one-way intake, not a live chat. Spanwork uses your contact detail to begin the follow-up you request.
Email follow-up is not end-to-end encrypted. If Spanwork can reach the Signal account you provide, any later Signal-to-Signal message is end-to-end encrypted under Signal's service.
Know the limits before you send.
Protected intake reduces exposure of the form contents. It does not hide the fact that a connection occurred.
Connection information remains visible
Cloudflare still receives ordinary connection data, including your IP address and request timing, while serving the page and delivering the ciphertext.
Browser encryption cannot protect text from a compromised device, browser, extension, or substituted site code before encryption.
The envelope does not provide forward secrecy. If the matching private key is later obtained and unlocked while an inquiry is retained, that historical inquiry could be opened.
Submitting does not make you anonymous or create an engagement, NDA, legal privilege, or guaranteed duty of confidentiality.
Do not send restricted material
- Passwords, authentication codes, recovery codes, tokens, private keys, or access credentials
- Payment card details, government identification, health records, financial records, or customer data
- Source code, production data, malware, exploit code, or unpublished security vulnerabilities
- Trade secrets, restricted material, or anything you are not authorized to disclose
Do not use this form for emergencies or vulnerability reports.