Client-Side File Encryption,
Simple and Secure

Protect sensitive files with password encryption powered by standard Web Crypto APIs. Runs 100% locally in your browser — zero file uploads, zero server tracking.

Launch Encryptor
Online

Choose a file to protect it with a password only you know.

Drop files here
or click to browse — encrypt a batch in one pass
FILE
filename.ext
0 KB
1 file ready
Password strength--
This password can't be recovered. If you forget it, the file cannot be decrypted. Store it safely.
filename.ext
Encrypting with AES-256-GCM
Encrypting file… 0%

Your file never leaves this device.

File encrypted
Saved as filename.ext.cipher
AES-256-GCM 0 KB 0.0s
FILE
filename.ext
0 KB
Incorrect password — authentication failed.

Designed for Maximum Privacy

Cipher leverages standard Web Crypto API primitives so you can secure files without trusting third-party cloud servers.

AES-256-GCM Encryption

Galois/Counter Mode (GCM) provides authenticated encryption, guaranteeing both high-speed encryption and data integrity checks.

PBKDF2 Key Derivation

Derives a cryptographic key from your password using SHA-256 with 250,000 iterations and a 16-byte random salt to prevent brute-force attacks.

100% Client-Side Executable

All binary processing takes place in your browser memory. Your files, passwords, and decrypted outputs never cross a network interface.

Cryptographic Container Spec

Cipher packs your encrypted data into a structured binary container format (`.cipher`).

MAGIC HEADER (4 BYTES)
ASCII "CPHR" (0x43 0x50 0x48 0x52)
Validates container format and prevents processing incompatible files.
VERSION & RANDOM SALT (17 BYTES)
1-byte Version (0x01) + 16-byte Random Salt
Salt generated via crypto.getRandomValues() for PBKDF2 key derivation.
INITIALIZATION VECTOR (12 BYTES)
96-bit Cryptographically Random IV
Ensures unique AES-GCM ciphertext generation per encryption pass.
METADATA & PAYLOAD
2-byte Big-Endian Length + Original UTF-8 Filename + AES-256-GCM Ciphertext
Preserves exact original filename for seamless restoration upon decryption.

Clear answers, private by design

Frequently Asked Questions

Everything you need to know before protecting your first file with Cipher.

Do my files ever leave my device?

No. Cipher performs encryption and decryption in your browser with the Web Crypto API. Files and passwords are not uploaded to a server.

What happens if I forget my password?

There is no password recovery path. Cipher is designed so only the password holder can unlock a file, so keep it in a trusted password manager.

Which files can I encrypt?

Any file type can be selected, including documents, images, archives, and media. The original filename is preserved inside the encrypted container.

Which cryptography does Cipher use?

Cipher derives a key with PBKDF2 and SHA-256, then protects the file with authenticated AES-256-GCM encryption using fresh random salt and IV values.