Authenticated file encryption in the browser. The server receives neither the passphrase nor plaintext.
Encrypt files
New files use BlindCrypt format v3. The public header, encrypted metadata, record order, record lengths, and every ciphertext record are authenticated.
Drop files here, or use the file picker. Up to 100 files and 64 MiB combined.
Maximum plaintext size: 64 MiB. The limit controls browser memory exposure.
KDF
PBKDF2, SHA-256
Iterations
900,000
Generated words
8
Cipher
AES-256-GCM
Passphrase assessmentEmpty
Enter a passphrase or generate one.
Store the passphrase before encryption. BlindCrypt has no recovery mechanism.
Decrypt or verify files
Format v3 verifies the complete container before download. Legacy v1 and v2 files remain readable with explicit limitations.
Drop files here. Buffered decryption supports 64 MiB combined; verification supports individual v3 files up to 4 GiB.
Malformed sizes, excessive KDF settings, inconsistent records, truncation, and trailing data are rejected before costly processing where possible.
Format v3 applies NFC normalization. Legacy formats use the passphrase exactly as entered.
Authenticated file information
Format
-
Name
-
Declared type
-
Integrity
-
Encrypted text
Messages use authenticated v3 encryption in a versioned text envelope. Limit: 64 KiB of UTF-8. Share the passphrase separately. Text is never rendered as HTML.
Strong settings. Generated passphrases are temporarily visible. Store one separately before confirming it. All secret fields clear after an operation.
Re-encrypt an existing file
Create a new v3 copy with a new passphrase or settings. No intermediate plaintext download. Limit: 64 MiB. This does not revoke old copies or establish missing legacy authenticity.
Legacy files otherwise restore as legacy-decrypted.bin. Keep your original encrypted copy until you have verified the replacement.
Large-file streaming
Up to 4 GiB, using 512 KiB records and a transactional save stream. Requires a browser with a local save-file picker. Other browsers retain the 64 MiB workflow above; the CLI is another option.
Choose a new output file. Decrypted bytes may be staged temporarily on disk; the destination is committed only after complete authentication. Cancellation cannot guarantee secure erasure of operating-system temporary files. Older BlindCrypt versions cannot open files beyond their 64 MiB limit.
Recipient-key sharing
Single-recipient JWE using RSA-OAEP-256 and AES-256-GCM. Limit: 16 MiB. This authenticates encrypted content, not the sender. New implementation: no independent cryptographic audit is claimed.
Create an identity
Keep the encrypted .bckey backup and its passphrase private. Only share the public .json file and independently confirm its fingerprint. Allow both downloads.
Encrypt for a recipient
A fingerprint copied only from the same untrusted key file does not verify the recipient.
Open a recipient file
Security model
Protected
Encryption and decryption run locally through WebCrypto.
Format v3 authenticates the exact public header as additional data for every record.
Filename and media type are stored inside a fixed-size encrypted metadata record.
Strict limits constrain headers, KDF cost, file size, record count, and passphrase length.
File operations have no telemetry, uploads, or runtime dependencies. Optional offline installation retrieves and caches only application assets.
Not protected
A compromised device, browser, extension, or hosting origin can capture plaintext or passphrases.
File size and public KDF parameters remain visible.
Legacy v1 and v2 metadata and whole-file completeness cannot be retroactively authenticated.
Clipboard contents may be exposed to other applications after manual copy.
Review the repository threat model and format specification before using BlindCrypt for high-value data.
Cancellation takes effect between cryptographic operations. Batch downloads may require browser permission for multiple files.
Offline edition not enabled. No user files or secrets are cached.