← Privacy Guides

Encryption

Encrypting individual files, folders and cloud storage

Protect specific files, a folder of them, or a cloud-synced folder on their own, so that a lost, synced or seized copy is unreadable without your passphrase or key — a layer on top of full-disk encryption, not a replacement for it.

  • Medium threat
  • Time 45 minutes to set up your first container or vault
  • Difficulty Moderate
  • Last verified against 0 age 1.3.2 (per the age project README install example)

What this protects, and what it doesn't

Protects

  • A container, vault or encrypted file that is copied, synced, lost or seized: without the passphrase or key the contents are scrambled.
  • Individual sensitive files on a disk you do not control — a cloud folder, a shared drive, a USB stick — or as a second layer on a device whose disk is already encrypted.
  • Files before you upload them: encrypt first, then sync, so the cloud provider only ever stores ciphertext.

Does not protect

  • A file that was already synced or shared in plaintext before you encrypted it. Copies the provider, your sync history, a backup or another person already hold are not reached by encrypting the local copy now.
  • The fact that an encrypted object exists. A container file, a vault folder or a .age / .gpg file is plainly an encrypted blob; it hides the contents, not that you are holding something encrypted (a VeraCrypt hidden volume is a separate feature for that).
  • Files while the container is mounted or the vault is unlocked: the contents are then readable to you, to any program you run, and to anyone who can use the running device.
  • Metadata around the encryption: a container's total size, individual file sizes and modification times, and the number of files all leak to some degree even when contents and (in some tools) names are encrypted.
  • The device against malware or against someone with access while you work. Pair this with full-disk encryption and a written threat model.
  • Your data if you lose the passphrase and any recovery key. No one, including the tool's authors, can recover it.

Prerequisites

  • You have already set up full-disk encryption (see that guide). File and container encryption is a layer on top of it, not a substitute.
  • A password manager or another safe place — separate from the encrypted data — to hold a long passphrase and any recovery key.
  • The official installer for the tool you choose, downloaded from the project's own site (links under Sources).

Step by step

  1. Pick the method that fits the job

    These are different tools for different shapes of problem, not a ranking. Choose by what you are protecting:

    • A set of files you keep together (a working folder, files on a USB stick): a VeraCrypt encrypted file container — one file that acts like a small encrypted drive you mount when you need it.
    • A folder you sync to cloud storage: Cryptomator, which encrypts each file separately so a sync app can upload the encrypted files one by one.
    • One or a few files to archive or send: age or GnuPG, which turn a single file into one encrypted file, protected by a passphrase or by a recipient's key.

    All four are free and open-source and run on Windows, macOS and Linux. You do not need more than one, and you can combine them (for example, an age-encrypted file stored inside a Cryptomator vault).

  2. A VeraCrypt container for a set of files

    A container is a single file that behaves like an encrypted drive. You mount it with your password, read and write files inside, then unmount it. VeraCrypt's Beginner's Tutorial creates one like this:

    1. Open VeraCrypt and click Create Volume.
    2. Keep the default Create an encrypted file container and click Next.
    3. Keep the default Standard VeraCrypt volume and click Next.
    4. Click Select File, choose a folder and a filename for the container, click Save, then Next. (An existing file at that path is overwritten, so use a new name.)
    5. Choose an encryption algorithm and a hash algorithm, or keep the defaults, and click Next.
    6. Enter the volume size and click Next.
    7. Type a strong password, retype it, and click Next. (The button stays disabled until both entries match.)
    8. Move the mouse around inside the window until the randomness bar is green — the tutorial suggests at least 30 seconds — then click Format, and OK when it finishes. Click Exit.

    To use it: in the main window pick a free drive letter or slot, click Select File, choose the container, click Open, then Mount, enter the password and click OK. When you are done, select it and click Unmount. While it is mounted, its contents are fully readable to the machine.

  3. A Cryptomator vault for a cloud folder

    Cryptomator encrypts each file on its own, which is what lets a cloud sync app upload the encrypted files one at a time. Its documentation describes creating a vault in a six-step wizard:

    1. Choose Create New Vault… and give the vault a name.
    2. Pick the storage location. To sync through the cloud, choose a folder inside your cloud provider's synced directory; Cryptomator detects some sync apps, or you can pick Custom Location. The docs stress that "Cryptomator is not a sync tool" — you still install your provider's own sync software.
    3. (Optional) Expert settings, which you can leave alone.
    4. Set a password. The minimum is 8 characters, but the docs recommend a longer passphrase, and note that Cryptomator cannot reset a lost password: without it your files stay inaccessible unless you have the recovery key.
    5. (Optional) Create and show the recovery key. Store it securely — ideally printed — because anyone who has it can open the vault. It is the only way to regain access if you forget the password.
    6. Finish. Unlock the vault with your password to get a normal-looking drive you can drop files into.

    Under the hood Cryptomator encrypts file contents in chunks with AES-GCM and encrypts filenames with AES-SIV, so the cloud sees only encrypted files and scrambled names.

  4. age for a single file

    age is a small modern tool that encrypts one file into one output file. It supports two modes.

    With a passphrase (good when only you need to open it later):

    age -p notes.txt > notes.txt.age

    Decrypt it with:

    age -d notes.txt.age > notes.txt

    age detects a passphrase-protected file automatically at decrypt time.

    With a key pair (good for sending a file to someone, or encrypting to yourself without typing a passphrase each time). Generate a key, which prints your public key:

    age-keygen -o key.txt
    # Public key: age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p

    Encrypt to a recipient's public key, then decrypt with the matching private key file:

    age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p notes.txt > notes.txt.age
    age -d -i key.txt notes.txt.age > notes.txt

    The public key above is the example from the project's own README — replace it with the real recipient's key. Keep key.txt (your private key) as carefully as any passphrase.

  5. GnuPG for a single file (passphrase mode)

    GnuPG (the OpenPGP implementation) is widely pre-installed on Linux and available for Windows and macOS. For a single file protected by a passphrase, the GNU Privacy Handbook uses the --symmetric option:

    gpg --output notes.txt.gpg --symmetric notes.txt

    GnuPG asks for a passphrase and derives the key from it. Decrypt with:

    gpg --output notes.txt --decrypt notes.txt.gpg

    The handbook notes two things worth keeping: the passphrase "should not be the same passphrase that you use to protect your private key", and symmetric mode is for cases where "the passphrase does not need to be communicated to others" — i.e. only you will open the file again. If you instead want to send the file to someone, use their OpenPGP public key rather than a shared passphrase.

  6. Make the passphrase the strong part

    With every tool here, the encryption is only as strong as the passphrase or key behind it. Follow what current guidance actually asks for, which is length, not punctuation puzzles. NIST's digital identity guidelines (SP 800-63B-4, §3.1.1.2) require that a password used on its own be "a minimum of 15 characters in length", say verifiers "SHOULD permit a maximum password length of at least 64 characters", and state that composition rules "SHALL NOT be imposed" and that users "SHALL NOT" be forced to change a password on a schedule.

    In practice: use a long passphrase — several random words, or a long random string from a password manager. The site's Password generator produces both locally in your browser. A short or reused password turns strong encryption into a weak lock.

  7. Plan for losing the key before you need to

    The same property that protects your files from an attacker destroys them for you if you lose the secret. There is no reset and no back door.

    • Store the passphrase in your password manager, and store any recovery key (Cryptomator) or private key file (key.txt for age) somewhere separate from the encrypted data — not inside the container, not in the same cloud folder.
    • Right after you create a container, vault or encrypted file, close it and reopen it to confirm the passphrase works and that you can read the contents back.
    • Keep a short note of which containers and vaults exist and where each key lives, in your password manager — not on the encrypted volume itself.

    Treat a recovery key or private key file like the data itself: anyone who has it, plus any old passphrase that still works, can open the encryption.

Common mistakes

  • Encrypting the local copy of a file that your cloud has already synced in plaintext, and assuming the plaintext copies are gone — they are still on the provider and in its version history.
  • Leaving a VeraCrypt container mounted or a Cryptomator vault unlocked all day: while it is open the files are as exposed as any unencrypted folder.
  • Storing the passphrase, the Cryptomator recovery key or the age private key inside the encrypted container or in the same cloud folder.
  • Choosing a short or reused password for a container because typing a long one is tedious.
  • Forgetting that filenames, file sizes and a container's total size can still reveal information even when the contents are encrypted.
  • Treating file or container encryption as a replacement for full-disk encryption instead of an extra layer on top of it.

Going further

For sending files, prefer recipient keys (age -r, or an OpenPGP public key with GnuPG) over a shared passphrase you have to transmit safely. For a folder you want to open on several machines through the cloud, Cryptomator's per-file encryption is designed for exactly that; for a fixed set of files on a drive or stick, a VeraCrypt container is simpler. On a Medium or High threat model, combine any of these with full-disk encryption and hardware security keys on the accounts that hold your cloud storage, and read the tool's own documentation (linked below) before relying on advanced features such as VeraCrypt hidden volumes.