AES-256 encryption in your browser. The file and passphrase never leave your device — only someone with the passphrase can open it.
AES-256 encryption in your browser. The file and passphrase never leave your device — only someone with the passphrase can open it.
Encrypting a file turns it into ciphertext that is useless without the key. GhostX derives that key from a passphrase you choose and encrypts the file with AES-GCM 256 on your device, producing a .gxenc file you can store in the cloud, attach to an email, or put on a USB stick without trusting whoever holds it. Tax returns, ID scans, contracts, medical records, backups: anything you would not want read if the account or device holding it were compromised.
Drop any file. It opens in the studio with Lock with a passphrase pre-selected. Nothing is uploaded.
Enter a passphrase twice. Deriving the key takes a second or two on purpose: the slow step is what makes guessing passphrases expensive.
Download the .gxenc. To open it, drop it back on GhostX and enter the passphrase.
Encryption is only as strong as the passphrase. Four or more random, unrelated words, or a long password from a password manager, resist guessing far better than a short word with symbols swapped in. Never reuse the passphrase from an account.
With AES-GCM 256, using a key derived from your passphrase by PBKDF2-SHA256 at 600,000 iterations with a random salt. Both run in your browser through the Web Crypto API. The output is a .gxenc file: a small header describing the key derivation, then the authenticated ciphertext.
No. Encryption and decryption both happen on your device; neither the file nor the passphrase is sent anywhere. You can watch the Network tab while it runs.
Drop it on GhostX — this page or the homepage — and enter the passphrase. The original file comes back with its name, and you can keep editing it in the studio.
The file cannot be recovered. There is no reset, no backdoor, and no copy on our side, because we never had one. Store the passphrase in a password manager.
Through a different channel from the file. Send the .gxenc by email or cloud storage, and the passphrase by phone, in person, or as a one-time GhostSend link that self-destructs after it is read.
A PDF password only applies to PDFs, and the result still opens in PDF readers that may handle it inconsistently. A .gxenc wraps any file — PDF, photo, audio, video, document, archive — so nothing about the contents, not even the file type, is readable without the passphrase.
Learn more: How to tell if a tool uploads your file