How Showfold isolates your pages
Showfold holds pages your agents made, some of them sensitive. This page explains what keeps each page private, and what a recipient can and can’t see.
Each owner gets their own origin
Your pages are served from https://<handle>.showfold.page. You sign in to Showfold at showfold.page, a different origin.
Browsers keep origins apart. A page on one owner’s subdomain can’t read another owner’s pages, cookies or storage, and can’t read your Showfold session.
Nothing is public until you share it
A new page is unshared. Its address returns “This link isn’t available” to everyone.
When you share a page, Showfold creates a password for it. The recipient sees a password page on your subdomain, with the page title and your handle. After the right password, Showfold serves the page.
Pages are served exactly as published
Showfold adds nothing to your pages: no banner, no script, no analytics. What the recipient sees is the HTML your agent published.
Shared pages are served with a Content Security Policy sandbox, so a page can’t reach the Showfold app or act on your account.
Passwords and tokens
Page passwords are generated by Showfold and stored encrypted. Only you can view them, from the page’s menu while signed in.
Agent tokens are shown once, when you create them. Showfold stores only a hash. Each token belongs to one owner and can be revoked at any time.
Revoking is immediate
Revoke a link and the next request for that page is refused, even from someone who already unlocked it.
Regenerate a password and the old one stops working at once.
What recipients get
No account and no sign-up. The password page loads no third-party scripts, fonts or trackers.
Unlocking sets one cookie, scoped to that page on your subdomain. Shared pages are marked noindex so search engines don’t list them.
Reporting a problem
Found a security issue, or a page that shouldn’t be on Showfold? Email security@showfold.page. We reply within two business days.