Lock a file or a note with a password before you email it, store it in the cloud or put it on a USB stick.
.enc added to its name; text is shown as encrypted text you can copy..enc file or paste the encrypted text, and enter the password.Encryption uses your browser's built-in Web Crypto engine, the same audited code that secures HTTPS connections. Your password is turned into a 256-bit key with PBKDF2-HMAC-SHA-256 using 600,000 iterations and a random 16-byte salt, which deliberately makes every password guess slow. The file is then encrypted with AES-256 in GCM mode using a random 12-byte nonce. GCM also adds a 16-byte authentication tag, so any change to the encrypted file, even a single bit, is detected and decryption refuses to continue instead of producing garbage.
The .enc format is simple and documented here so you are never locked in. It starts with the 6 ASCII bytes MDDENC, then a version byte (1), the iteration count as a 4-byte big-endian number, the 16-byte salt and the 12-byte nonce. Everything after that is the AES-GCM output (ciphertext followed by the tag), and those 39 header bytes are authenticated as additional data. Inside the encryption sits one byte for the content type (file or text), a 2-byte name length, the original file name in UTF-8, and the file itself, so even the file name is hidden. Encrypted text is the same bytes written as Base64. Anyone can rebuild a decryptor from this description with any standard crypto library.
Example: encrypting taxes-2025.pdf (2.0 MB) produces taxes-2025.pdf.enc, just 58 bytes larger plus the length of the name. Key derivation takes about a second on purpose; the encryption itself is fast. The whole file is held in memory while it is processed, so the practical size limit depends on your device's memory. Files up to about 100–200 MB usually work on a computer; phones handle less.
What happens if I forget the password?
The file cannot be opened. There is no reset, backdoor or recovery, because the password is never stored anywhere, not even on this site. Keep it in a password manager or written down somewhere safe.
Why does it say "wrong password or damaged file"?
With authenticated encryption, a wrong password and a modified file look the same: the check fails and nothing is decrypted. Check the password (it is case-sensitive) and make sure the file was copied completely.
How strong is the encryption?
AES-256-GCM is a widely used standard for protecting sensitive data. In practice, the weak point is the password: a short or common password can be guessed despite the slow key derivation. Use a passphrase of four or more random words or 16+ random characters. Our Password Strength Checker can help.
Can I open the .enc file without this website?
Yes. The format is fully described above and uses only standard algorithms (PBKDF2-SHA-256 and AES-256-GCM), so it can be decrypted with common tools such as Python's cryptography library or OpenSSL-based code. You can also save this page for offline use.
Is my file uploaded?
No. Everything runs in your browser, so the file and password never travel over the internet. You can even disconnect from the network after the page has loaded.