WaxSeal is a companion product to StegoSafe, built for teams and organizations. StegoSafe hides a secret inside a photo and keeps everything on your device forever. WaxSeal answers a different need: when an organization has to send a secret to a specific person and still keep control of it afterwards — revoke it, expire it, or prove who opened it.

It does that by turning the trust model around. Where StegoSafe never lets the secret leave your device, WaxSeal deliberately separates the carrier from the content.

Two products, two trust models

StegoSafeWaxSeal
Built forIndividualsTeams & organizations
Where the secret livesInside the photo, on your deviceIn a vault your organization controls
The photo carriesThe full encrypted secretOnly a sealed reference
After you send itIt’s out of your handsYou can revoke, expire, or limit it
Best whenYou want nothing to touch a serverYou need control, recall, and an audit trail

Neither is a better version of the other. StegoSafe stays fully on-device — that promise doesn’t change. WaxSeal is for the cases where an organization needs to hand a secret to someone and keep authority over it, and accepts that the encrypted content is held in a vault to make that possible.

How WaxSeal works

  1. Seal. You encrypt the content and store the ciphertext in a WaxSeal vault under your organization’s control. The photo you share carries only a small sealed reference — not the data itself.
  2. Send. The photo travels like any ordinary image: over chat, email, or anywhere else. On its own it reveals nothing and opens nothing.
  3. Open. The recipient’s app reads the reference, authenticates with their device (Touch ID / Face ID), and — if policy allows right now — retrieves and decrypts the content on their device.

Because the content sits behind the vault rather than inside the image, the rules travel with it.

What the vault gives you

  • Burn after reading — the content is destroyed the moment it’s opened.
  • Limited reads — allow a fixed number of opens, then it’s gone.
  • Expiry — content that stops working after a deadline, whether or not anyone opened it.
  • Recipient binding — a seal that only a designated person’s device can open.
  • Instant revocation — kill access after you’ve already sent the photo. The image keeps existing; it just stops opening.
  • Audit trail — a record of who opened what, and when.

None of this is possible once a secret has fully left your hands. Keeping the content in the vault is what makes recall, expiry, and audit real instead of aspirational.

Run it your way

The vault is the part your organization controls, and you decide where it lives:

  • Self-hosted — run the WaxSeal vault on your own infrastructure. The encrypted content never leaves servers you operate, which is the natural fit for teams with strict data-residency or compliance requirements.
  • Managed — let us host the vault for you, so there’s nothing to deploy or maintain. You still get the same revocation, expiry, and audit controls.

Either way, the WaxSeal apps come from the App Store like any other app — the choice is only about where your vault runs.

Security

  • AES-256-GCM authenticated encryption for all content.
  • PBKDF2-SHA256 key derivation (600,000 iterations).
  • Device-bound authentication — opening requires the recipient’s own device biometrics (Touch ID / Face ID).
  • No plaintext markers in the carrier image, consistent with the StegoSafe approach.

Availability

WaxSeal is in active development and available to select teams as an early-access preview. It is a separate product from the StegoSafe apps, and will be distributed through the App Store — with your choice of a self-hosted or a managed vault.

If your team needs controlled, revocable secret-sharing, get in touch: [email protected].

WaxSeal and StegoSafe are products of NEXATECH AI EFFICIENCY SERVICES LTD., British Columbia, Canada.