Runs in your browser · nothing uploaded

Lock any file with a passphrase.

Turn a file into a .vault that only your passphrase opens. Encryption happens in this tab with your browser's own crypto engine; the file never touches our server.

AES-256-GCMPBKDF2-SHA256 · 600,000 roundsUp to 200 MB per fileWe never ask for your seed phrase.
Drop files to lockor click to choose · up to 200 MB each · stays on this device
Use 4+ random words or 16+ mixed characters.
Key stretching takes about a second per file.

There is no reset. If you forget the passphrase, the file cannot be recovered by us or anyone. Write it down somewhere safe.

Open format

You're not locked in to us.

A .vault file is a short header plus AES-GCM chunks. Everything needed to open it — except your passphrase — is in the file. The script below opens one with plain Node.js, no packages.

0 · 8 bytesmagic "VAULTBX" + version byte 0x01
8 · 1key derivation id: 1 = PBKDF2-HMAC-SHA256
9 · 4iterations, uint32 big-endian (600,000)
13 · 16random salt
29 · 8random nonce prefix
37 · 4chunk size in plaintext bytes (4 MiB)
41 · 4metadata ciphertext length
45 · …metadata: AES-256-GCM of JSON {name, type, size, mtime}, IV = prefix ‖ uint32(0). Your filename is encrypted too.
… chunkschunk i (1…n): AES-256-GCM, IV = prefix ‖ uint32(i), each chunk size + 16-byte tag
AADfirst 41 header bytes + 1 flag byte (2 = metadata, 1 = last chunk, 0 = other). Changing any parameter, reordering, or cutting off the end makes decryption fail loudly.
Offline decrypt script (Node 18+, no dependencies)
FAQ

Good questions.

Is anything uploaded?

No. Files are read with the browser's File API, encrypted with Web Crypto, and handed back as a download. The page's Content-Security-Policy only allows it to talk to its own server, and this site has no upload endpoint. You can load the page, turn off your network, and it still works.

Why 200 MB?

The locked file is assembled in your browser's memory before download. 200 MB is a safe ceiling for phones and older laptops. For bigger archives, split them first or use a desktop tool such as age or VeraCrypt.

How strong is it?

AES-256-GCM is the standard authenticated cipher; a wrong passphrase or any change to the file is detected. The weak point is always the passphrase: 600,000 PBKDF2 rounds slow guessing down, but a short or reused passphrase can still be cracked offline by anyone who gets the .vault file.

Should I lock my seed phrase in here?

We never ask for your seed phrase, and we'd rather you keep it offline: written on paper or metal, stored somewhere safe. If you do encrypt a backup, use a long unique passphrase and never store the passphrase next to the file.

What's hidden and what isn't?

Contents, original filename, type and size (inside the metadata) are encrypted. The .vault file's own size is visible, so someone can estimate the original size within a few bytes.