GhostXStudio tools

Lock any file with a passphrase.

AES-256 encryption in your browser. The file and passphrase never leave your device — only someone with the passphrase can open it.

Encrypting a file turns it into ciphertext that is useless without the key. GhostX derives that key from a passphrase you choose and encrypts the file with AES-GCM 256 on your device, producing a .gxenc file you can store in the cloud, attach to an email, or put on a USB stick without trusting whoever holds it. Tax returns, ID scans, contracts, medical records, backups: anything you would not want read if the account or device holding it were compromised.

How it works

  1. 1

    Drop any file. It opens in the studio with Lock with a passphrase pre-selected. Nothing is uploaded.

  2. 2

    Enter a passphrase twice. Deriving the key takes a second or two on purpose: the slow step is what makes guessing passphrases expensive.

  3. 3

    Download the .gxenc. To open it, drop it back on GhostX and enter the passphrase.

Pick a strong passphrase

Encryption is only as strong as the passphrase. Four or more random, unrelated words, or a long password from a password manager, resist guessing far better than a short word with symbols swapped in. Never reuse the passphrase from an account.

Frequently asked questions

How is the file encrypted?

With AES-GCM 256, using a key derived from your passphrase by PBKDF2-SHA256 at 600,000 iterations with a random salt. Both run in your browser through the Web Crypto API. The output is a .gxenc file: a small header describing the key derivation, then the authenticated ciphertext.

Is my file or passphrase uploaded?

No. Encryption and decryption both happen on your device; neither the file nor the passphrase is sent anywhere. You can watch the Network tab while it runs.

How do I open a .gxenc file?

Drop it on GhostX — this page or the homepage — and enter the passphrase. The original file comes back with its name, and you can keep editing it in the studio.

What if I forget the passphrase?

The file cannot be recovered. There is no reset, no backdoor, and no copy on our side, because we never had one. Store the passphrase in a password manager.

How should I share the passphrase?

Through a different channel from the file. Send the .gxenc by email or cloud storage, and the passphrase by phone, in person, or as a one-time GhostSend link that self-destructs after it is read.

How is this different from password-protecting a PDF?

A PDF password only applies to PDFs, and the result still opens in PDF readers that may handle it inconsistently. A .gxenc wraps any file — PDF, photo, audio, video, document, archive — so nothing about the contents, not even the file type, is readable without the passphrase.

Related tools

Learn more: How to tell if a tool uploads your file