📦

Encrypt / Decrypt a File

Encrypt any file with AES-256-GCM using a passphrase-derived key (PBKDF2 200k iterations) and decrypt it back — all in your browser. The file never leaves your device.

AES-256-GCM with a PBKDF2-derived key (200k iterations). The encrypted file embeds the salt, IV and original filename, so decrypting only needs the password. Files never leave your browser.

Encrypt a sample file

Encrypt a small built-in text file with the passphrase and download the resulting .enc file that can only be opened with that passphrase.

Runs the actual Encrypt action, so a note.txt.enc downloads. Decrypting it here with the same passphrase restores the original.

FAQ

How strong is the encryption?

It uses AES-256-GCM with a key derived from your passphrase via PBKDF2 with 200,000 iterations. That’s a strong, standard design for protecting data at rest.

What if I lose the passphrase?

There is no recovery path. The key is derived from your passphrase at use time and never stored, so without it the .enc file cannot be decrypted. Keep it somewhere safe.

What is inside the .enc file?

The original filename, a random per-file salt, an IV and the AES-256-GCM encrypted data. That self-containment is why decryption only needs your passphrase.

Can anyone else decrypt my file?

Only with your passphrase. The file never transits a server and the key isn’t stored, so the .enc file is the only thing that exists after you encrypt.

Updated 2026-08-10 · Runs in your browser — your data never leaves this page unless the tool explicitly says it makes a network check.