(Dokumentation på engelska)
What it does
The File Encryptor locks any file with AES-256-GCM authenticated encryption, entirely in your browser. You pick a password; the tool derives a 256-bit key from it with PBKDF2-SHA256 (100,000 iterations) and a fresh random 16-byte
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
, then seals the file with a random 12-byte IV. The output file issalt (16 B) + IV (12 B) + ciphertext + GCM tag (16 B) - exactly 44 bytes larger than the input. Decryption reverses the process: it reads the saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
and IV, re-derives the key from your password, and verifies the GCM authentication tag before releasing a single byte of plaintext. 100% client-side - the file and the password never leave your machine.How to use it
- Pick Encrypt or Decrypt with the toggle.
- Drag a file into the drop zone (or click it to browse). Any file type works.
- Type a password. Use the eye button to show or hide it.
- Press Encrypt file / Decrypt file. The result downloads automatically, with the original and output sizes compared so you can see the 44-byte overhead.
Examples
Encrypt a report:
invoice.pdf (218.4 KB) + password correct horse battery staple → invoice.pdf.enc (218.5 KB, +44 B)
Decrypt it back:
invoice.pdf.enc + the same password → invoice.pdf, byte-for-byte identical to the original
Wrong password:
invoice.pdf.enc + any other password → Decryption failed: wrong password or corrupted file. - the GCM tag check fails and nothing is written.
Good to know
- Zero server contact: everything runs via the browser’s Web Crypto API. No uploads, no logs, no accounts. You can disconnect from the network and the tool still works.
- Why AES-256-GCM? It is an authenticated cipher: the 16-byte tag proves the file was not modified after encryption. Tampering with any byte - ciphertext, IV, or
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
- makes decryption fail loudly instead of returning corrupted data. - Why PBKDF2 with 100k iterations? Key stretching makes each password guess expensive, so brute-forcing a stolen
.encfile from a short password is dramatically slower than trying raw keys. - Password strength is the whole security model. There is no key recovery, no escrow, no reset. If you forget the password, the file is unrecoverable - by design.
- The same file encrypted twice produces different output every time, because the
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
and IV are freshly random per encryption. - Related tools: Password Generator (pick a strong password), Password Strength Analyser (check one),
HashHashA one-way function that maps data of any size to a fixed-length digest. Same input, same digest; any change, different digest; not reversible.
Generator (checksumschecksumsA short digest computed from a block of data, compared after transfer or storage to detect corruption. Changing one bit changes the checksum.
).