Encrypted File Vault
Protect a small set of local files in one downloadable package. This tool derives a non-exportable AES-256 key from your passphrase using PBKDF2-HMAC-SHA-256 with a fresh random salt, then encrypts file names and bytes together with AES-GCM. Opening authenticates the entire bundle before listing or offering any file for download. The .tanivault format is version 1 of this tool, not a ZIP or a general-purpose vault standard.
Key features
- Encrypt up to 20 small files and their names in a single versioned package
- Use fresh 16-byte salt, 12-byte IV, PBKDF2-HMAC-SHA-256 at 600,000 iterations, and AES-256-GCM with a 128-bit tag
- Authenticate the format header as associated data and the full file bundle before showing any name or byte
- Reject wrong passphrases, tampered packages, unsafe names and duplicate aliases
- Download restored files individually after successful authentication
- Keep operations in this browser tab with no account or server upload
How to use
- Choose up to 20 local files, or load the two example text files.
- Enter a long unique passphrase of at least 12 characters and confirm it; download the .tanivault package.
- Switch to Open package, choose the downloaded .tanivault file and enter the same passphrase.
- Wait for full authentication; review the restored file list and download the files you need.
- Clear the workbench when finished. Keep the package and passphrase separately; a forgotten passphrase cannot be recovered here.
Use cases
- Carry several small personal documents as one encrypted download
- Share a small file set while communicating its passphrase through another channel
- Test how authenticated encryption rejects a changed package
- Keep filenames out of the visible package header
Frequently asked questions
Can this open encrypted ZIP, 7z or other vault formats?
No. It reads only this tool's version 1 .tanivault format. Its package is not a ZIP and other apps may not recognize it.
What if I enter the wrong passphrase or the package is damaged?
AES-GCM authentication fails and no file names or bytes are returned. The same error is shown for a wrong passphrase and tampering; it does not reveal which occurred.
Can you recover a forgotten passphrase?
No. There is no account, recovery key or server copy. Keep a separate secure record of the passphrase and test a restore before deleting originals.
What does the package reveal before decryption?
The version marker, random salt and IV, and total package length are visible. File names, file count and file content are encrypted. The total length can still suggest approximate data size.
What limits and name rules apply?
At most 20 files, 8 MiB per file, 32 MiB total, 33 MiB package. Only normalized NFC basenames up to 255 UTF-8 bytes are accepted; path separators, reserved device names, controls and case-insensitive duplicates are rejected. No folder hierarchy or compression is retained.
Does a 12-character passphrase guarantee security?
No. The minimum prevents very short input, but an easy-to-guess passphrase can still be attacked offline. Use a long, unique, randomly generated passphrase. This browser tool is not a substitute for a reviewed backup or key-management system.
Privacy
File bytes and passphrases are processed in this browser tab; this tool does not submit them to the site server or analytics. The passphrase is not saved in localStorage. Browsers and extensions still control the local environment, so use a trusted device and browser.
Comments & questions