Loading...
Use arrow keys to navigate, Enter to select, Escape to close menu.
Loading...
Straightforward answers about how our free encryption tools work and how we protect your privacy.
Zero-knowledge means we never have access to your unencrypted data or your encryption keys. All encryption happens in your browser using AES-256-GCM before anything leaves your device. Your 256-bit encryption key is derived from your passphrase in your browser and never sent over the network. Even if our servers were compromised, your data would still be protected — without your key, the encrypted output is indistinguishable from random data. A brute-force attack against a 256-bit key would require checking 2^256 (about 1.1 × 10^77) possible combinations — far more than the number of seconds in the age of the universe.
Yes. AES-256 is standardized by NIST in FIPS 197 and approved for protecting U.S. government classified information up to TOP SECRET. The "256" refers to the key size in bits — there are 2^256 possible keys, about 1.1 × 10^77. Even a computer checking one trillion keys per second would need roughly 10^47 times the 13.8-billion-year age of the universe to work through them. We use AES in GCM mode (standardized in NIST SP 800-38D), which provides both confidentiality and integrity verification. No known quantum algorithm breaks AES-256. Grover's algorithm cuts the effective key strength to 128 bits, and those operations must run one after another, so it offers little practical speed-up.
Your original plaintext data and encryption keys never leave your device. Encryption happens locally via the Web Crypto API before any network request is made. If you use our storage feature, what reaches our servers is AES-256-GCM ciphertext — a scrambled binary blob that, without the 256-bit key, is cryptographically indistinguishable from random data. We store this encrypted data with no identifying metadata attached. You set the expiration time, and the encrypted data is automatically deleted after that period.
No account needed — you can start encrypting in under 10 seconds. Visit the tools page, type or upload your data, and encrypt immediately. We believe privacy tools should be available without barriers: no signup, no email, no personal information collected. The encryption runs entirely in your browser, so there's nothing to log into — your device does all the work.
Yes. Once the page loads, you can disconnect from the internet and keep using the tools. All encryption operations use the Web Crypto API — a W3C standard built into every modern browser since 2014 — and run entirely on your processor. Nothing you type or upload is sent to us while you encrypt or decrypt; encrypted output leaves your device only if you choose to store or share it. You only need internet to initially load the page.
We cannot recover your key — and we designed it that way. Keys are derived locally with PBKDF2 (RFC 8018 / PKCS #5) and 100,000 iterations of HMAC-SHA-256, and are never transmitted. If you lose your key, the AES-256-GCM encrypted data becomes permanently inaccessible to everyone, including us. This is a feature of zero-knowledge architecture, not a bug. With 2^256 possible keys, a computer checking one trillion keys per second would need about 10^47 times the age of the universe to find yours. We recommend storing keys in a password manager.
This website (zeyrovault.com) is currently ad-free. We plan to display non-intrusive, clearly labeled advertisements (for example via EthicalAds) once the site reaches sufficient traffic, to cover hosting and development costs. The tools at tools.zeyrovault.com are — and will remain — completely ad-free. We do not sell data, charge for features, or require accounts. Your privacy isn't the product.
Encryption happens on your device, not on our servers. Most services encrypt data on their servers using keys they manage — which means they could potentially access your plaintext. ZeyroVault encrypts using AES-256-GCM entirely on your device via the Web Crypto API before any data is transmitted. We never see your original content, your password, or your 256-bit encryption key. Even if compelled by a court order, we have no plaintext data or keys to hand over. This is a fundamental architectural difference, not a policy choice.
Any browser that supports the Web Crypto API — including Chrome, Firefox, Safari, Edge, Opera, and Brave, on desktop and mobile. The Web Crypto API is a W3C Recommendation, so it is a formal web standard tested across implementations. A browser that no longer receives security updates cannot run the tools.
Yes. Our How It Works page documents the full encryption process in detail. We use only publicly-reviewed standards: AES-256-GCM (NIST FIPS 197 + NIST SP 800-38D) for encryption and PBKDF2 (RFC 8018 / PKCS #5) with 100,000 iterations of HMAC-SHA-256 for key derivation. We do not use proprietary or custom algorithms. For technical verification, open your browser's Developer Tools (F12) and go to the Network tab — you'll see that no readable data is transmitted during encryption. The entire process is client-side, and the source code can be inspected in your browser.
No account, no setup — just open and start encrypting.