File Encryptor

100% private — runs on your device, never uploaded. Works offline once loaded.

Encrypt any file with a password using strong AES-256-GCM encryption, and decrypt it later with the same password. Everything happens in your browser with the built-in Web Crypto API — your file and password are never uploaded.

What actually happens to the file

This tool doesn't just scramble the file's contents — it runs a proper authenticated encryption scheme, AES-256-GCM, using the Web Crypto API built into your browser. Your password itself is never used as the encryption key directly; instead it's run through PBKDF2 with 200,000 iterations to derive a 256-bit key, which deliberately makes each guess computationally expensive so brute-forcing the password is impractical even with GPU clusters. The "GCM" part adds an authentication tag, so if even a single byte of the encrypted file is altered or corrupted, decryption fails outright rather than silently producing garbage — you know immediately if a file was tampered with or damaged in transit.

When you'd reach for this instead of a zip password

Standard zip "password protection" is notoriously weak — older zip encryption (ZipCrypto) can be cracked in minutes with freely available tools, and even AES-encrypted zips depend entirely on the archiving software's implementation quality. This tool exists for situations where that isn't good enough: sending a tax document or contract over email, backing up a sensitive file to a cloud drive you don't fully trust, storing an ID scan or private key on a USB stick, or handing a file to someone over a channel you can't fully secure. Because encryption and decryption both happen locally in the browser, the plaintext file and the password never have to be transmitted to any server to get the job done.

  • Sharing sensitive documents (tax forms, contracts, medical records) over email or chat
  • Encrypting a backup before uploading it to cloud storage
  • Protecting private keys, credential exports, or config files on removable media

What the output file looks like

The encrypted result bundles the salt (used in the PBKDF2 key derivation), the initialization vector, and the ciphertext together into a single downloadable file. That means the file is completely self-contained — you don't need to separately track a salt or IV to decrypt it later, only the password. The trade-off is that the encrypted file is a few dozen bytes larger than the original, and it will no longer open in whatever application reads the original format until it's decrypted back.

Password strength is the entire security model

AES-256 itself is effectively unbreakable by brute force, which means the real weak point is always the password, not the algorithm. A short or common password undermines even perfect encryption, because an attacker only needs to guess the password, not break AES. Use a long, unique password — ideally one made with a password generator rather than something memorable — and store it somewhere separate from the encrypted file itself, since anyone who has both defeats the purpose entirely.

Frequently asked questions

How strong is it?

It uses AES-256-GCM with a key derived from your password via PBKDF2 (200,000 iterations) — the same standard used by secure apps.

What if I forget the password?

There is no recovery — the encryption is done entirely on your device with no backdoor. Keep your password safe.

How strong is the encryption?

It uses AES-256-GCM with a key derived from your password via PBKDF2 at 200,000 iterations — the same standard used by password managers and secure messaging apps, not a toy cipher.

What happens if I forget the password?

There is no recovery mechanism by design — encryption happens entirely on your device with no backdoor or server-side copy, so a forgotten password means the file is permanently inaccessible.

Can I encrypt any type of file, including large ones?

Yes, the tool works on any file type since it encrypts raw bytes rather than interpreting the format, though very large files (several gigabytes) may be slower since everything is processed in your browser's memory.

Will the encrypted file still open in its original application?

No — the output is an encrypted binary blob, not a valid document, image, or archive, until you run it back through this tool's decrypt mode with the correct password.

Is this the same as a password-protected zip file?

No, and it's stronger — many zip tools still use weak legacy encryption that can be cracked quickly, whereas this uses authenticated AES-256-GCM with a deliberately slow key derivation to resist password-guessing attacks.

How will I know if a decrypted file was corrupted or tampered with?

GCM includes a built-in authentication tag, so decryption will fail with an error rather than silently returning corrupted data if the file was altered or the wrong password was used.

Advertisement