Encrypt a file
Encrypt or decrypt a file in the browser with AES-256-GCM, up to 5 GB, output .lock / .enc. The file and passphrase are not uploaded. Open the page and use it.
How to encrypt a backup locally
Before a certificate pack, export, or config with keys goes into cloud storage, people search for “encrypt file online.” If the tool uploads the file and encrypts on a server, the plaintext window grows. This page uses the Web Crypto API for streaming AES-256-GCM. The encrypted result downloads to this machine.
The passphrase is stretched with PBKDF2 (100,000 iterations, SHA-256). One file up to 5 GB. You can also encrypt a short paragraph on the same page. To decrypt, drop the .lock or .enc file back in and enter the original passphrase; the filename and contents are restored.
- The file and passphrase are not uploaded as product data — keep the download yourself
- A forgotten passphrase cannot be recovered; generate a long one with the password generator
- Short secrets (passwords, recovery codes) fit a self-destructing message better than a whole-file flow
FAQ
Does online file encryption upload my file?
No. Encryption and decryption run in the browser. The file and passphrase are not uploaded as product data. The result downloads as .lock or .enc — keep it somewhere you trust.
Which algorithm is used, and what is the file size limit?
AES-256-GCM authenticated encryption. The passphrase is stretched with PBKDF2 (100,000 iterations, SHA-256). One file up to 5 GB, processed in chunks. You can also encrypt a short paragraph on the same page.
Can I decrypt if I forget the passphrase?
No. There is no plaintext or passphrase backup on the server. Use a long passphrase and store it in your own password manager.
How do I send an encrypted file to someone else?
Send the .lock or .enc file through a drive or email. Send the passphrase on a different channel. Short secrets fit a self-destructing message; this tool is for local backups and whole-file encryption.