Free tools and connected services

Start with a key and a decoy.
Choose your tool.

Encrypt locally without an account. Cloud vault storage requires an account and uploads encrypted data. Hosted encryption APIs, online services called by your software, receive messages and passwords to process them.

01 / In your browser

One file. Two control files.

Create an encrypted file (ciphertext) and two control files, which select the real message or a decoy, your chosen fake. Both passwords are required together.

Web + SDK / Interactive illustration
ONE CIPHERTEXT / SAME PASSWORD PAIRciphertext + password 1 + password 2
+ the control file you choose
Real messageSelected by the real control file.

Illustration only. The password pair stays the same when switching control files.

Free / No account

Encryption, without the sign-up.

Type a message or upload a file. Keep your control files separate and safe. Local decoy suggestions stay in the browser. The optional live engine sends only the detected type label to request a suggestion.

Encrypt or decrypt ↗
02 / On your machine

Choose the way you work.

Local tooling and browser tooling are separate from hosted API processing.

03 / Connected tools

Online, with explicit boundaries.

These tools do not share the browser encryptor’s account-free, local-only boundary.

01

Cloud vault

Account-required storage. Secrets are encrypted client-side before upload, using one password and AES-GCM, an encryption method that also checks for changes. The separate encryptor creates real and decoy control files.

Explore the vault ↗
02

Telegram bot

The bot/protect-seed scheme uses matching pairs: real password with real control file, or decoy password with decoy control file.

Read the bot guide ↗