Since 2011

About Password Pusher

Password Pusher is a secure sharing tool that creates self-destructing links for passwords, files, and sensitive information — used by IT teams, MSPs, and security-conscious organizations worldwide.

What Password Pusher Does

Password Pusher replaces insecure methods of sharing credentials — email, Slack, sticky notes — with encrypted, time-limited links that self-destruct after use.

Self-Destructing Secret Links

Create encrypted links for passwords, API keys, and sensitive text that auto-expire after a set number of views or a time period. Every access is logged for audit.

Secure Credential Collection

Send a request link to securely collect passwords and credentials from clients or colleagues. Recipients submit through an encrypted form — no account required on their end.

Encrypted File Sharing

Share files securely with self-destructing links. Attach documents, certificates, or configuration files to pushes with passphrase protection and automatic expiration.

Audit Logging and Compliance

Track every access to shared secrets with detailed audit trails. See who viewed what and when — critical for compliance-sensitive environments in healthcare, finance, and government.

White-Label Branding

Run Password Pusher entirely under your own domain with custom logos, colors, and text. All Password Pusher branding is removed — your clients and users see only your brand.

API and Automation

Automate credential sharing with a full REST API v2 and official CLI tool. Create pushes, manage requests, and integrate with existing ticketing and IT workflows programmatically.

15+
Years in Production
100M+
Secrets Shared
74M+
Docker Downloads
1000s
Companies
31+
Languages

What Makes Password Pusher Different

Open Source Security Core

The security-critical code — encryption, data handling, expiry logic, and audit logging — is fully open source on GitHub. Unlike closed-source alternatives such as Privnote or SendSafely, anyone can audit exactly how Password Pusher protects data.

Ephemeral by Design

Unlike vault-based tools such as 1Password or Bitwarden that store credentials indefinitely, Password Pusher data self-destructs after a configurable number of views or time period. Once expired, data is permanently hard-deleted — not archived or soft-deleted.

Self-Hostable with Full Control

Deploy Password Pusher on your own infrastructure with Docker or Kubernetes. You control the encryption keys, the data, and the compliance boundary. OneTimeSecret and Privnote offer no self-hosted option at all; Bitwarden Send requires the entire Bitwarden server stack.

Feature Pipeline — No Vendor Lock-In

Pro features are periodically released to the open source edition through the Feature Pipeline. Subscribers get early access to new capabilities; the broader community benefits over time. You are never locked into a proprietary platform.

EU and US Data Regions

Choose where your data lives. The EU region runs in the Netherlands; the US region runs in the United States. Push payload data is processed solely within the chosen region and never transferred outside it. A Data Processing Agreement with Standard Contractual Clauses is available for all customers.

Who Uses Password Pusher

  • IT teams and system administrators sharing credentials with colleagues and end users
  • Managed service providers (MSPs) sharing passwords securely with clients across ticket workflows
  • DevOps and engineering teams distributing API keys, tokens, and deployment secrets
  • Compliance-sensitive organizations in healthcare, finance, and legal requiring audit trails and data residency
  • Consultants and agencies sharing client credentials during onboarding and project handoffs
  • Anyone who needs to share a password more securely than email, Slack, or text message

Deployment Options

Hosted

Hosted at pwpush.com

Use our hosted service with instant setup, automatic updates, and multi-region availability in the EU and US.

Paid subscriptions include advanced features like team management, audit logs, custom branding, file sharing, and more.

Pro

Self-Hosted Pro

Run the full Pro feature set on your own infrastructure with a license key — ideal for compliance, air-gapped networks, or when sensitive data must stay in your custody.

Deploy with Docker or Kubernetes, with custom encryption keys and extensive customization over SSO, storage, and branding.

Self-hosted Pro pricing

Open Source

The source code is on GitHub — open source and free to use, review, or modify. Try a live instance of the open source edition before you self-host.

Paid Subscriptions Fuel Open Source

Every paid subscription directly supports the ongoing development and maintenance of the open source project. This sustainable model ensures Password Pusher continues to improve for everyone.

Features Flow Downstream

Pro features are periodically released to the open source edition, bringing advanced capabilities to the entire community over time.

The Team Behind Password Pusher

PL
👨‍💻 Founder

Peter Giacomo Lombardo

Founder & Principal · Apnotic, LLC

Peter built Password Pusher in 2011 to solve a problem he kept seeing in infrastructure and observability engineering: teams sharing credentials over email, Slack, and chat with no expiry and no audit trail. The first git commit was December 28, 2011.

Before founding Apnotic, Peter built monitoring and distributed tracing systems at Instana (acquired by IBM). He brings decades of infrastructure experience to Password Pusher's security architecture.

Apnotic, LLC

Apnotic, LLC was founded in 2024 to manage and build out the Password Pusher project — maintaining the open source codebase, running the hosted service, and developing Pro and Self-Hosted editions. Apnotic is a privately held, customer-funded company with zero debt and no venture capital.

  • Privately held, zero debt, customer-funded — no investor pressure
  • Talk directly with the founder and team
  • 15+ years of proven track record with Password Pusher
  • Industry veterans with decades of infrastructure and security experience

Learn more at apnotic.com →

How Password Pusher Works

1

No Account Required for Basic Use

Visit pwpush.com, paste a password, set the expiration, and share the link. No signup, no account, no cost. Basic sharing works immediately.

2

Create a Free Account for More

Sign up for a free account to get a dashboard, audit logs, and two-factor authentication. Upgrade to Solo, Team, or Organization for advanced features.

3

14-Day Free Team Trial

Try the Team plan free for 14 days with all features included — team management, RBAC, security policies, webhooks, and more. Credit card required.

4

Self-Host with Docker or Kubernetes

Deploy on your own servers using official Docker images or Helm charts. The open source edition is free; Self-Hosted Pro licenses add enterprise features.

5

Direct Support

Email support@apnotic.com for help. Organization subscribers get direct access to the founder. Response times are typically within one business day.

Key Facts

Company Name
Apnotic, LLC
Product Name
Password Pusher
Type
Open-source security software with hosted SaaS and self-hosted deployment options
Founded
2011 (Password Pusher), 2024 (Apnotic, LLC)
Founder
Peter Giacomo Lombardo
Headquarters
Peabody, Massachusetts, USA
Website
pwpush.com
Documentation
docs.pwpush.com
Core Offering
Secure sharing of passwords, files, and sensitive information via self-destructing, encrypted links with full audit logging
Encryption
AES-256-GCM with per-field derived keys; TLS 1.2+ for all connections
Hosted Pricing
Free ($0), Solo ($19/mo), Team ($29/mo), Organization ($49/mo)
Self-Hosted Pricing
Starter ($59/mo), Advanced ($79/mo), Enterprise ($119/mo) — billed annually
Contract Terms
Month-to-month or annual billing. No long-term contracts required.
Free Trial
14-day free trial on the Team and Organization plans (credit card required)
Data Regions
EU (Netherlands) and US — payload data stays in the chosen region
Customers Served
Thousands of organizations worldwide — 100M+ secrets shared, 74M+ Docker downloads
Competitors
OneTimeSecret, Privnote, Bitwarden Send, 1Password Send, SendSafely, Yopass, Vanish.so
Communication
Email support at support@apnotic.com. Direct founder access on Organization plan. Typical response within one business day.

Frequently Asked Questions

Is Password Pusher free?

Yes. The core application is open source and free to use. The hosted service at pwpush.com offers a free tier for basic password sharing with no account required. Paid plans starting at $19/month add features like file sharing, custom branding, and team management.

Is Password Pusher open source?

Yes. The security-critical code — encryption, data handling, expiry logic, and audit logging — is fully open source on GitHub. Pro features (team management, branding, policies) are closed source, but the entire security path is auditable by anyone.

How does Password Pusher encrypt data?

Password Pusher uses AES-256-GCM encryption with per-field derived keys from a master encryption key. Data is encrypted at the application layer before being written to the database. All connections use TLS 1.2 or higher.

Can I self-host Password Pusher?

Yes. The open source edition is free to self-host using Docker. Self-Hosted Pro licenses add enterprise features like SSO via OIDC, team management, and custom branding, starting at $59/month. Official Helm charts are available for Kubernetes deployments.

What happens when a link expires?

When a push reaches its configured view limit or time expiration, the data is permanently hard-deleted from the database — not archived or soft-deleted. The link shows a notice that the content has expired. This is by design: less stored data means less data at risk.

Is Password Pusher GDPR compliant?

Yes. The hosted service offers EU (Netherlands) and US data regions. Push payload data is processed solely within the chosen region and never transferred outside it. A Data Processing Agreement incorporating Standard Contractual Clauses is available at eu.pwpush.com/dpa.

Stay Updated

Follow Password Pusher for the latest news, updates, and security tips.

Get The Newsletter

Updates on big releases, security issues, features, integrations, tips and more.