The short answer: Send only the encrypted proof pack through a channel you already trust for financial files. Tell the reviewer to open it in ZecBooks Reader. Never send the UFVK “for convenience.”
Sharing checklist
Confirm the recipient
Name the person and firm. Proof packs are still sensitive financial data even when they cannot spend.
Send the pack file only
Use your normal secure file path for tax documents. Do not attach vault databases or key material.
Point them at Reader
Reviewers open the pack in ZecBooks without importing your vault. That is the intended path.
Respect expiry
If the engagement ends, let the pack expire. Export a new scoped pack if they need a refresh.
What never to send
- Seed phrases
- UFVK / UIVK strings
- Raw wallet databases
- Screenshots that show full unredacted keys
Common mistakes
- Forwarding the same pack to a wider mailing list than the engagement needs.
- Posting packs in public GitHub issues or Discord.
- Assuming expiry means the recipient deleted every local copy — treat channels as sticky.
Ready for Mac?
Download ZecBooks and keep spend keys out of the books workflow.