Private forms · files · human + agent hand-offs
Request what you need. Send it privately. Close the passage. End-to-end encrypted, for a named recipient, for a limited time.
How it works
Wormhole
Waiting
01Ask
Make a form and choose who receives it: you, a teammate or your agent. Send the link.
Everything a private exchange needs, and nothing that would keep a copy.
Answers and files are encrypted on the sender's device. Only the recipient's enrolled devices can open them. We can't.
Every submission has its own deadline, from five minutes to a month. Reuse a form without building a response archive.
Send to a person or to an AI agent. Senders always see which, and what an agent may do with their answers.
Structured questions, private notes, images and documents. Masked fields for account numbers and codes.
Live hand-offs go straight to a ready screen and are never stored. Mailbox mode waits, encrypted, until it's opened.
Add a generated or custom password. Nothing about the form shows until it's unlocked.
Agents create forms over MCP and get a signed ping the moment something arrives. Answers never pass through us in the clear.
Your logo, colour and introduction. The recipient and privacy notice never change, so branding can't hide who receives.
Account references, IDs and documents from clients, without them landing in an inbox.
Credentials, briefs and private notes between people who need them once.
Your agent asks for the missing details, gets a ping in seconds, and carries on.
For agents
Agents create forms over MCP or JSON, wait for a signed webhook, and decrypt answers with their own key. The sender is told an AI receives the answers and what it may do with them.
// MCP tool call
create_form({
spec: {
title: "Missing details",
fields: [
{ name: "account", type: "private",
label: "Account number" }
]
},
submission_deadline: "24h"
})
// → { url: "https://…/f/…" }
// webhook, about 3 seconds after sending
{ "type": "exchange.accepted",
"exchange": "…", "deadline": "…" }Wormhole holds encrypted data only until it is received or expires. Then it is gone, and nobody here ever had the key.
End-to-end encryption
ECDH P-256 and AES-256-GCM in the browser, bound to the form, the recipient and the deadline.
Deleted on receipt
The mailbox deletes itself when the recipient confirms, or at the deadline. No backups, no versions.
Content-free alerts
Emails and webhooks say something is waiting. Never what, or from whom.
Explicit recipients
A link alone never opens anything. Only the named recipient's enrolled devices can.
Wormhole is invite-only while we pilot it with agencies, consultants and teams that build with agents.
Request access