Hand Over Client Credentials Without Leaving Them in Email
Send CMS, hosting, and social media passwords to clients securely. Data is encrypted in the browser and consumed upon viewing.
The Retained-Message Problem
When completing a project, emailing passwords or sending them in Slack leaves a permanent record in the client's inbox. If the client's email is ever compromised in the future, those credentials could be stolen, leading to potential liability.
A Professional Handoff
Hush ensures credentials are not retained in chat histories. When the client clicks "Reveal Secret", the data is returned once and permanently erased from the live database.
Temporary Handoff Workflow
1. Create scoped access
Create a specific, limited-permission account for the client where possible, rather than handing over a master administrative root password.
2. Send with expiry
Generate a Hush link with an appropriate expiry time. Send it to the client, advising them to store the credential in their password manager immediately.
3. Rotate after handoff
If you shared temporary access, rotate or revoke the credentials once the handoff is successfully completed.
Know the Limits
- Hush cannot verify the identity of the client opening the link.
- It is not a password manager, a compliance solution, or a substitute for proper access controls.
- It cannot prevent the client from taking screenshots, losing the password, or having their device compromised.
Learn more about How it Works, our Security, and Privacy.
Read our guides on securely sharing passwords or handling recovery codes. View all use cases, or see our IT Helpdesk use case.