Skip to content

How it works

From original work to a trusted viewing session.

Supported image Capsule flow

Share Capsules lifecycle steps

Share Capsules separates the act of publishing from the decision to unlock. Creators keep their work portable, while Viewers open it through trusted services that check access before anything protected is shown.

Creator workflow

Step 1

Content creation

The creator makes the work with the tools they already use, whether that means images, video, HTML, PDFs, or another format they want to share more intentionally.

Creator workflow

Step 2

Capsule creation

The creator tool wraps the work in an encrypted Capsule and signs the trust policy, so the package carries clear instructions about how it may be opened.

Creator workflow

Step 3

Publish capsule

The encrypted Capsule can be placed on an ordinary website. The Host can share the file, but it cannot read the protected content inside it.

When someone visits the hosted page

Viewer workflow

Step 4

Connection

A Viewer connects through the official tool, reviews the access requirements, and chooses whether to opt in to this Capsule’s trust policy.

Viewer workflow

Step 5

Policy check

A trusted provider checks only what this Capsule requires, such as account status, consent, limits, or creator-selected conditions.

Viewer workflow

Step 6

Key release

If access is approved, the broker releases a one-time opening key to that connected Viewer. The Host never receives it.

Viewer workflow

Step 7

Decryption

The Viewer opens the Capsule locally and shows the protected work inside its own trusted viewing surface.

Capsule access rules

One Capsule format, several ways to decide when it opens.

Capsules can be configured with time, limit, and trust policies. These policies can be used alone or combined to define the access rules for decryption. The Viewer opens the encrypted content only when every required policy is satisfied.

A Time Capsule, Limit Capsule, Trust Capsule, or Combined Capsule allows creators to configure how they want their protected content shared.

Time Capsule

Allows creators to set opening and closing dates. The Capsule opens only during that configured access window.

Limit Capsule

Allows creators to limit how many times protected content can be viewed, either across all viewers or per viewer account.

Trust Capsule

Allows creators to require a viewer trust check before content opens. The trust score considers recent usage patterns and quick human challenges that help distinguish people from bots.

Combined Capsule

Combines selected rules so time, limit, and trust requirements must all pass before the key is released.

At viewing time

Opens normally

The current time, counters, account, device, and trust checks satisfy the signed policy.

Locked by rule

A time window has not started, has ended, or an opening limit has already been reached.

Quick check needed

The viewer is otherwise eligible, but current confidence is too low to release the key yet.

Blocked for risk

Recent high automation-risk behavior can keep access blocked even if a challenge is attempted.

Trust checks help reduce automated access, but they are not a perfect guarantee. They do not prove that a viewer is a unique person, generally trustworthy, or guaranteed to use the content well.

The participants

One flow, deliberately separated responsibilities.

The journey works because each participant has a narrow job.

Share Capsules operates the first reference services, but Capsule and CTX are designed as an open protocol. Official tools can choose recognized providers and brokers without forcing every implementation into one closed ecosystem.

Creator

Creates

Original work using the tools they already know, such as image, video, HTML, PDF, or other supported formats.

Chooses what they want to share more intentionally.

Creator tool

Secures

The original work, creator signing key, trust policy, and freshly generated content key.

Produces the encrypted, policy-bearing Capsule locally.

Host website

Publishes

Public fallback content and the encrypted Capsule file.

Can distribute the Capsule without needing Viewer identity, the key, or plaintext.

Viewer

Requests

A person visits the hosted page and asks to open the Capsule through a compatible Viewer.

Starts as an ordinary visitor until the policy and key path complete.

Official registry

Recognizes

The providers and brokers that official tools are willing to use by default.

Lets official Viewers refuse unknown, suspended, or revoked services before private information is shared.

CTX Protocol

Coordinates

The policy check and key-release conversation between the Viewer, provider, and broker.

Keeps the Host out of the trust and key path.

Trust Provider

Evaluates

The trust policy and only the consented evidence needed for that request.

Returns a limited policy result instead of raw account history.

Key Broker

Releases

Protected content-key material, release state, and exact short-lived authorization.

Wraps the content key to the authorized Viewer device; it does not render the work.

Trusted Viewer

Opens

The account connection, consented evidence, device keys, released content key, and rendered plaintext.

Coordinates access and decrypts locally, outside the Host page.

At viewing time

The key moves only after the policy is satisfied.

Downloading an encrypted Capsule is not itself a protected view. The content becomes readable only after authorization and device-bound key release.

  1. Step 1

    Verify before disclosure

    The Viewer fetches the Capsule, validates its signature and declared trust policy, and checks that the required services are recognized before sharing account evidence.

  2. Step 2

    Ask for informed consent

    The Viewer explains which policy conditions will be checked and asks whether the visitor wants to opt in for this opening.

  3. Step 3

    Authorize the exact request

    The Trust Provider evaluates the creator’s policy for this Capsule, revision, action, account, and registered device. Approval is short-lived and cannot authorize unrelated content.

  4. Step 4

    Release and render locally

    The Key Broker validates the authorization and wraps the content key to the Viewer device. The Viewer decrypts in its isolated surface; the Host does not receive the key or plaintext.

Available now

Secure image sharing is ready to use.

Create an account, protect an image, publish the protected Capsule on your site, and let eligible viewers open it with the Share Capsules Viewer. The hosted Share Capsules services handle the account, access, and key-release steps for the supported V1 flow.

Protect images
Turn supported image files into protected Capsules that can be published on ordinary web pages.
Choose access rules
Use open access, date windows, opening limits, revocation, and trust checks depending on how you want the image to be shared.
Use the hosted service
You do not need to run your own servers for the supported flow. Share Capsules provides the account, access, and key-release services.
Still coming later
More content types, more browsers and devices, more provider choices, and more advanced publishing workflows.

What this architecture cannot promise

An authorized person can still photograph, record, reproduce, or misuse rendered content. Share Capsules aims to make anonymous bulk access harder and releases more accountable; it does not make visible work impossible to copy or prove future human intent.

Question the design

Confirm this change

This action may not be reversible.