Zero-Trust Data Protection

Secure Team Handoff: XChaCha20-Poly1305

Zero-Knowledge Collaboration for Enterprise Teams

100% Local Processing
Trusted by 10,000+ professionals · $0 Free / $99/mo Teams
Airplane Mode Verified
Local Execution
Secure Team Handoff — XChaCha20-Poly1305 encrypted session transfer between team members

AI Summary / Key Takeaways

Verified Zero-Trust Logic

"Collaborate on sanitized documents without compromising zero-trust architecture. Export your active RAM session map, encrypt it locally using military-grade XChaCha20-Poly1305 and an Argon2id derived key, and share it with a teammate so they can reveal the text on their end. Available in the Site Workspace."

What encryption algorithms does Team Handoff use?
Does the encrypted session map ever touch your servers?
What happens if someone intercepts the handoff payload?

Enterprise-Grade AI Privacy

Add custom redaction rules and priority support with PRO.

GO PRO

The Hidden Cost of AI Collaboration Without Zero-Trust

Your analyst masks a contract before sending it to ChatGPT — but when the AI response lands, the reviewer on the other side of the company sees tokens like [NAME_1] and [COMPANY_3]. They have no session map. They cannot read the answer. The fix most teams reach for — a shared cloud account or a central database — immediately violates zero-trust principles and fails SOC2 CC6.1 and HIPAA §164.312(e). There is no middle ground. Until now.

How Secure Team Handoff Works

1

Local Key Generation

Your browser derives a highly secure cryptographic key from your team's shared passphrase using Argon2id, the industry standard for memory-hard key derivation.

2

Client-Side Encryption

The entire PII session map (which ties tokens like [NAME_1] to real values) is encrypted locally using the XChaCha20-Poly1305 cipher before leaving your device.

3

Encrypted Transfer

The resulting ciphertext is exported as a portable string. Even if intercepted, it remains mathematically impossible to decrypt without the local passphrase.

What Teams Achieve with Local PII Masking

"The Argon2id integration is brilliant. We can pass session maps across our engineering team in Slack, knowing it's just encrypted ciphertext. No central server means zero breach risk."

D

David R., Security Architect

Verified User

"Finally, we can collaborate on scrubbed contracts without losing the ability to un-mask the names later. The offline-first design made our compliance audit a breeze."

E

Elena M., Lead Legal Ops

Verified User

"We were using a shared Google Doc to store session tokens — a clear HIPAA violation we only noticed after an audit. Team Handoff eliminated that risk entirely. The PHI never touches a server."

P

Priya K., HIPAA Compliance Officer

Verified User

"Our M&A team was wasting 20 minutes per document manually re-inserting deal terms after getting AI analysis. With Team Handoff, the CFO pastes the payload and Reveal does it in seconds."

M

Marcus T., CFO Office Analyst

Verified User

"Distributed team across 4 time zones. We pass encrypted session payloads over Slack. Zero servers involved. Our InfoSec team approved it in a single review — fastest security sign-off I've ever seen."

S

Sofia L., Remote Engineering Lead

Verified User

Swipe to read more

Supported Formats & Limitations

Supported Formats

Encrypted JSON Blob (XChaCha20-Poly1305)

System Limitations

  • Requires pre-shared encryption passwords for handoff decryption
  • Sessions expire implicitly based on team protocol (not enforced by a server)
  • Cannot be recovered if the handoff password is lost

The Real Problem with AI Collaboration in Regulated Teams

Consider three real workflows that break down the moment compliance enters the picture:

The instinct is to fix this by storing the session map in a shared database or a synced cloud folder. But that immediately violates HIPAA §164.312(e), SOC2 CC6.1, and GDPR Article 25 (Privacy by Design). You cannot have both collaboration and zero-trust if a server holds the keys. Secure Team Handoff solves this without the tradeoff.

Cryptographic Parity: Argon2id + XChaCha20-Poly1305

Instead of trusting our servers to hold your keys, we empower your browser to act as a secure enclave. Your team's shared passphrase is run through Argon2id — the winner of the Password Hashing Competition and the NIST SP 800-132 recommended algorithm — to derive a robust encryption key. The volatile session map is then encrypted using XChaCha20-Poly1305, an AEAD cipher that provides both confidentiality and authentication in a single pass.

Local
Key Derivation
AEAD
Authenticated Cipher
0 Bytes
Server Storage

The Trust Architecture: No Cloud in the Loop

The diagram below shows what actually happens during a Team Handoff. Every node where PII could leak has been eliminated by design.

Analyst Device
Encrypts session map
locally in browser
XChaCha20 payload
Slack / Email
Sees only ciphertext
Zero PII
Same payload
Reviewer Device
Decrypts locally,
Reveal in browser
PrivacyScrubber servers — never in the loop

Compliance-Ready by Design

Team Handoff was built to pass compliance reviews, not just security ones. Here is how it maps to the major frameworks your legal and audit teams care about:

FrameworkControlHow Team Handoff Satisfies It
HIPAA§164.312(e) — Encryption in transitPHI session map is encrypted (XChaCha20-Poly1305) before leaving the device. Network only sees ciphertext.
SOC2CC6.1 + CC6.7 — Logical access & transmission encryptionNo centralized credential store. Key derivation uses Argon2id. Zero server receives plaintext PII.
GDPRArt. 25 — Privacy by Design & DefaultData minimization is architectural: no PII is processed server-side at any point in the handoff chain.
ISO 27001A.8.24 — Use of cryptographyUses AEAD with authenticated tag. Key length and algorithm (XChaCha20) exceed A.8.24 minimum cryptographic control requirements.
NISTSP 800-132 — Password-based key derivationArgon2id with configurable memory, iterations, and parallelism parameters — compliant with NIST recommendations for password hashing.

Team Handoff vs. Shared Cloud Accounts

Most teams working around the token-isolation problem reach for one of three workarounds — all of which fail a compliance audit:

MethodServer Access to PII?HIPAA Safe?Setup Time
Team Handoff (PrivacyScrubber) Never Yes30 seconds
Shared Google Doc with token map Google sees it No5 minutes
Shared Notion / Confluence database Notion sees it No10 minutes
Manual re-insertion (copy-paste)Depends on methodConditional15–25 min/doc

Workflows by Industry

Legal Teams

Paralegals scrub client names and entity identifiers from contracts before running them through AI drafting tools. The reviewing partner imports the encrypted payload and uses Reveal to read the final clause in context — without client data ever touching a third-party server.

Healthcare

Billing teams mask PHI — patient names, DOBs, MRNs — before querying AI for ICD-10 suggestions. The attending physician imports the session payload to review recommendations mapped back to actual patients. Full HIPAA §164.312(e) compliance throughout.

Finance & M&A

Deal analysts mask company names and financial figures before feeding them into AI valuation models. The CFO or managing director imports the encrypted session to review the AI output with real deal terms restored — in seconds, not 20-minute manual re-insertions.

Flat Pricing. No Per-Seat Surprises.

Secure Team Handoff is included in the TEAMS plan at $99/month flat — no per-seat pricing, no usage caps on handoff payloads. Whether your team is 3 people or 300, the price does not change. This is a deliberate architectural choice: because everything runs in the browser, we have zero marginal cost per user, and we pass that directly to you.

For organizations requiring on-premise deployment, air-gapped operation, or a source code license, the ENTERPRISE plan includes all Team Handoff capabilities with GRC support and a dedicated compliance review package.

Feature Reliability & Audit

This enterprise feature is powered by our Local-First Sanitization Engine. Unlike legacy cloud DLP tools, PrivacyScrubber processes your Secure Team Handoff: XChaCha20-Poly1305 logic 100% within your browser's V8 sandbox. This architectural decision ensures that even the most complex detection patterns never expose raw data to an external API.

WASM 1.2 Audited
Zero-Trace RAM Session

Airplane Mode

Verified feature operational integrity without network connectivity.

Step-by-Step Guide

How to use this feature

2 min total
1

Scrub Document

Scrub any document containing PII in PrivacyScrubber as usual.

2

Generate Ciphertext

Click 'Export Team Session'. Your browser will encrypt the session map using your team's shared passphrase and output a cryptographic payload.

3

Share Securely

Send the encrypted payload to your colleague via Slack, Teams, or email alongside the scrubbed AI response.

4

Import & Reveal

Your colleague clicks 'Import Team Session', pastes the payload, and enters the shared passphrase to reconstruct the session map locally.

What you need: PrivacyScrubber TEAMS subscription A shared team passphrase

Frequently Asked Questions

What encryption algorithms does Team Handoff use?

Team Handoff relies on Argon2id for password hashing and key derivation, combined with XChaCha20-Poly1305 for authenticated encryption. These modern cryptographic primitives provide robust protection against side-channel and timing attacks, entirely within your browser.

Does the encrypted session map ever touch your servers?

No. We provide the cryptographic engine, but the encryption happens on your local CPU. The resulting ciphertext is handled entirely by you — you can paste it into an email, Slack, or internal wiki. We never see the data, the key, or the ciphertext.

What happens if someone intercepts the handoff payload?

The payload is protected by XChaCha20-Poly1305 encryption. Without the shared team passphrase (used by Argon2id to derive the decryption key), the payload is indistinguishable from random noise and mathematically impossible to decrypt.

Is Team Handoff available on the Free or PRO tier?

No. Secure Team Handoff is an exclusive feature of the TEAMS and ENTERPRISE tiers, designed specifically for multi-user collaborative workflows and organizational compliance.

Does Team Handoff satisfy HIPAA and SOC2 requirements?

Yes. Because the PII session map is encrypted client-side before any transfer, no Protected Health Information (PHI) traverses the network in plaintext. This satisfies HIPAA §164.312(e)(1) for encryption in transit and supports SOC2 CC6.1 (logical access) and CC6.7 (data transmission encryption). The Argon2id key derivation also meets NIST SP 800-132 recommendations for password-based key derivation.

How many team members can use Team Handoff simultaneously?

TEAMS plan is priced at $99/month flat with no per-seat limits. All team members can export and import encrypted session payloads. There is no hard limit on the number of simultaneous users.

What if we lose the team passphrase?

The passphrase is never stored anywhere — not on our servers, not in your browser. If it is lost, the encrypted payload cannot be recovered. We recommend storing the passphrase in a team password manager (1Password, Bitwarden, or your enterprise vault) under a shared vault entry.

Protect Your Team's AI Prompts in Under 30 Seconds

Protect My Team

No server uploads. Works 100% offline in browser RAM.

Support
Sanitize Files
Mask AI Prompt