Client-side AES-256-GCM file encryption, running entirely in your browser via the Web Crypto API. This page never talks to a server — nothing you encrypt here ever leaves your machine.
● 100% client-side · no uploads · no backend<filename>.enc.
.enc file produced by this page (or by the real Python
FileEncryptor in the repo — the container format is byte-identical)
and the password it was encrypted with.
cryptbox/encryption.py — using the browser's native
crypto.subtle instead of PyCryptodome. Same algorithm, same
parameters, same on-disk container format:
| Cipher | AES-256-GCM (authenticated encryption) |
| Key derivation | PBKDF2-HMAC-SHA256, 100,000 iterations, 32-byte key |
| Salt | 16 random bytes, unique per file |
| Nonce / IV | 12 random bytes, unique per file |
| Auth tag | 16 bytes, verified on decrypt (tamper-evident) |
| File layout | [salt(16)][nonce(12)][tag(16)][ciphertext] |
python gui/dashboard.py for the full experience.