Every link knows who's on the other end.
Indy replaces 'paste a URL and hope' with verified, identified access. Recipients confirm by email, get a 30-day session, and you always know exactly who opened what.
Recipients verify before they ever see the artifact.
When you add someone, Indy emails them a one-time verify link. Once they confirm, their browser holds a 30-day session — so they're never re-prompted, but you always have a name attached to every open. No more 'someone from an unknown device opened your deck.'
- One-time verify link per recipient, sent from your verified domain
- Sessions persist 30 days, then re-verify — set custom windows down to one day
- Revoke any recipient instantly; their session dies server-side
Allow a whole company without naming everyone.
Selling into a buying committee you can't fully enumerate? Allowlist a domain and anyone with a verified email at that company can self-serve in — still identified, still tracked, just without you hand-entering each address.
- Add acme.com and every verified @acme.com visitor gets access
- Each one still shows up individually in your activity feed
- Mix named recipients and domain allowlists on the same artifact
Download permissions, custom session length, instant revoke.
You decide whether recipients can download the source, how long their access lasts, and when it ends. Change your mind after sending — settings apply on their next open, and the URL never changes.