Command line
Encrypt, decrypt and manage control files from your terminal.
Explore the CLI ↗Encrypt locally without an account. Cloud vault storage requires an account and uploads encrypted data. Hosted encryption APIs, online services called by your software, receive messages and passwords to process them.
Create an encrypted file (ciphertext) and two control files, which select the real message or a decoy, your chosen fake. Both passwords are required together.
Illustration only. The password pair stays the same when switching control files.
Type a message or upload a file. Keep your control files separate and safe. Local decoy suggestions stay in the browser. The optional live engine sends only the detected type label to request a suggestion.
Encrypt or decrypt ↗Local tooling and browser tooling are separate from hosted API processing.
Encrypt, decrypt and manage control files from your terminal.
Explore the CLI ↗Access deny.sh from your browser workflow.
View the extension ↗Use TypeScript, Python, Go or Rust in your own process.
Choose a code library ↗These tools do not share the browser encryptor’s account-free, local-only boundary.
Account-required storage. Secrets are encrypted client-side before upload, using one password and AES-GCM, an encryption method that also checks for changes. The separate encryptor creates real and decoy control files.
Explore the vault ↗The bot/protect-seed scheme uses matching pairs: real password with real control file, or decoy password with decoy control file.
Read the bot guide ↗