Cryptbox 2.0 — Live Demo

Client-side AES-256-GCM file encryption, running entirely in your browser via the Web Crypto API. This page never talks to a server — nothing you encrypt here ever leaves your machine.

● 100% client-side · no uploads · no backend
Encrypt a file
Pick any file and a password. It's encrypted in memory with AES-256-GCM (key derived via PBKDF2-HMAC-SHA256, 100,000 iterations) and downloaded as <filename>.enc.
Decrypt a file
Pick a .enc file produced by this page (or by the real Python FileEncryptor in the repo — the container format is byte-identical) and the password it was encrypted with.
How this works
This demo reimplements exactly one module of the full project — cryptbox/encryption.py — using the browser's native crypto.subtle instead of PyCryptodome. Same algorithm, same parameters, same on-disk container format:
CipherAES-256-GCM (authenticated encryption)
Key derivationPBKDF2-HMAC-SHA256, 100,000 iterations, 32-byte key
Salt16 random bytes, unique per file
Nonce / IV12 random bytes, unique per file
Auth tag16 bytes, verified on decrypt (tamper-evident)
File layout[salt(16)][nonce(12)][tag(16)][ciphertext]
The full project — RSA-2048 key management, RSA-encrypted secure sharing between users, RSA-PSS digital signatures, encrypted metadata, a FUSE-mounted virtual encrypted drive, a CLI, and this same encryption flow behind a Flask dashboard — is on GitHub. Clone it and run python gui/dashboard.py for the full experience.