SecureRCVD

Wire instructions · sealed channel · never money movement

Stop wiringthe wrong place.

A lookalike reply on a real thread is enough. The funds leave. The clawback fails. SecureRCVD is the sealed channel where only a counterparty you connected with — stepping up with their authenticator — can send or open wire instructions. No stranger can push “updated banking details” at you. You still call back before anyone funds.

Who can send
Connected counterparties only
Who can open
That party + authenticator
Email carries
Notify only — no bank fields
Money movement
Never
Still required
Your callback
Why this exists

One wrong set of instructions. One irreversible wire.

Nobody has to break your bank. A lookalike domain replies on a real thread with “updated wiring instructions.” It looks like your counterparty. It isn't. After funds clear, clawback is slow and often fails — and the only question left is who authorized the send.

01

Wrong party, real-looking thread

A hijacked reply on a real thread reads like your counterparty — because it is the real thread. Nobody notices during the wire. They notice at reconciliation, after the funds have cleared.

02

The PDF never expires

The second you attach it, you’ve lost custody of the numbers. Phones, downloads, FYI forwards. No revoke, no expiry, and no honest answer to “who has these right now?”

03

Encrypted email solves the wrong half

TLS in transit isn’t sealed at rest. The message lands and decrypts into a mailbox — often a shared closing inbox with delegated access. The account number sits in plaintext exactly where it does damage.

What this is

Only the counterparty you connected can touch the numbers.

No open directory. No stranger can push “updated instructions” at you. Both sides connect on purpose, hold their own keys, and step up with an authenticator to send or open. Key fingerprints let you confirm you're still talking to the same counterparty. The human callback before funding stays — we are not trying to replace it.

We do
  • Encrypt wire fields on your machine, before they leave it
  • Store ciphertext and metadata only — no readable copy on our side
  • Require your authenticator on login, send, and open
  • Let you revoke access and set expiry after the fact
  • Keep every bank field out of email — notifications only
  • Show fingerprints so you can confirm your counterparty’s keys
  • Record send, open, and reopen so there’s a trail
We don’t
  • Move money, initiate wires, or hold funds
  • Act as a bank or a payment processor
  • Read your instruction plaintext
  • Replace your callback before funding
  • Sell you a certification we don’t have
Path

Four moves, and no attachment in the thread.

  1. 01

    Connect the real counterparty

    Invite on both sides. Keys on each device. Authenticator on each end. No open directory — nobody can push instructions at you uninvited, and you only exchange inside that connection.

  2. 02

    Type the wire details

    You fill in the fields the way you always have. They encrypt in your browser before anything is sent. The readable version never leaves your machine.

  3. 03

    We hold a sealed record

    Our server stores a block it cannot read, plus who sent it and when. Your counterparty gets an email that says an instruction is waiting — and nothing else.

  4. 04

    They open it — then you still call

    Only the connected counterparty with their authenticator can unlock. Open is logged. Then the out-of-band callback confirms the numbers themselves, exactly like your policy already says.

Security posture

Proof over badges.

Here’s what we’ve tested, what passed, and what’s still open. The last one is open on purpose — an external pen test hasn’t happened yet, and we’d rather you read that here than find out in a questionnaire.

27/27
Internal auth pen matrix
20/20
Product smoke, real end-to-end decrypt
PASS
Unauthenticated surface recon
OPEN
External hired pen test

Client-side encryption, device-held keys, TOTP step-up on login, send, and open. Key fingerprints you can compare. Session rotation, rate limiting, a written threat model, and a backup restore drill with matching record counts. What we don’t have: a SOC 2 report. There isn’t one until an independent auditor writes one.

Design partners

Built for people who still call back.

We’re taking a small number of design partners: desks that move real wire instructions and want them out of email. Written beta rules, honest limits in writing, and a standing no-go on unsupervised high-value closings until the external pen test is done. If you want a vendor that tells you what it isn’t ready for, that’s the whole pitch.

SecureRCVD · Black Coffee Project

SecureRCVD shares wire instructions. It does not transfer money, initiate wires, or hold funds. It does not replace out-of-band verification — call back before funding. Not a bank. Not a payment processor. Not SOC 2 certified until an independent report exists.