Encrypt a file online
Drop in a photo, video, or archive. This tab encrypts in 1 MB blocks with AES-256-GCM and writes .lock or .enc. The file and passphrase never leave the browser. No sign-up. Short secrets belong on a one-time Burn-Link, not here.
Local compute · not uploaded
Drop a file, or click to choose
Any type · 5 GB max per file
1,000 lines max, 10 KB per line. A failed line does not stop the batch.
Ciphertext lives only in the file you download. A forgotten passphrase cannot be recovered. Any block that fails authentication stops the run and will not write partial plaintext.
0%
Download name
Confirm the browser saved the file. A forgotten passphrase cannot be recovered.
Do not send the passphrase on the same channel as the ciphertext. Use Burn-Link for a short secret on its own.
Check where the file went
Chunked reads, key derivation, and AES-256-GCM all finish in the current tab. The file, passphrase, and filename are not sent as an HTTP request and are not written to analytics.
.lock. Decrypt restores the original name from the header.
Before you encrypt a file
No. Chunked reads, PBKDF2 derivation, and AES-256-GCM all finish in the current tab. The file, passphrase, and filename are not sent as an HTTP request and are not written to analytics. The server receives neither this plaintext nor this ciphertext.
.lock.
After you lock it
Generate a file passphrase locally first. Do not stuff a short secret into a .lock file—use a one-time link. Plaintext, keys, and files are not uploaded by default.