Enclave is a privacy-focused lightweight encryption web-app that allows you to encrypt and decrypt any file type locally in your browser without any data ever leaving your device. Built with security and privacy as core principles.
Enclave provides authenticated XChaCha20-Poly1305 password encryption and OpenPGP public-key encryption for any file type. Files, passwords, and keys remain inside the browser throughout encryption and decryption.
Key Features:
- 🔐 XChaCha20-Poly1305 Encryption - Implemented with Libsodium
- 📁 Universal File Support - Encrypt any file type (documents, images, videos, etc.)
- 📦 Chunked Processing - No application-imposed limit; practical limits depend on the browser, memory, and encryption method
- 🌐 Local Processing - No file, password, or key upload and no runtime API connection
- 🎯 No Application Data Collection - No analytics, account, database, or telemetry in the application
- 📱 Cross-Platform - Works on any device with a modern browser
- 🆓 Open Source - Fully auditable code under CC0 license
- Visit the 🔒 Enclave web application
- Choose your encryption method: Password or PGP Key
- Drag and drop your file or click to select
- Enter a strong password (minimum 16 characters with numbers, uppercase, and special characters)
- Click "Encrypt File" to secure your data
- Download the encrypted file with
.encryptedextension
- Select "Decrypt" mode
- Upload your encrypted
.encryptedfile - Enter the same password used for encryption
- Click "Decrypt File" to restore your original file
- Download the decrypted file
For maximum security, passwords must include:
- ✅ At least 16 characters
- ✅ At least one number
- ✅ At least one uppercase letter
- ✅ At least one special character
Password-encrypted files use a recognizable Enclave magic number so the app can select the current format. Changing the marker makes the file invalid, but the marker itself is not secret. OpenPGP output is identifiable as OpenPGP ciphertext.
Safari, browsers on iPhone, and memory-constrained mobile browsers may fail on large files because of browser and WebAssembly memory limits. There is no reliable universal 1 GB threshold. Enclave does not use a service worker.
- Password Recovery: If you forget your password, your files cannot be recovered. There is no "forgot password" option by design.
- Browser Compatibility: Use a currently supported desktop browser. Safari and WebKit have additional limitations.
- Memory Usage: Password mode processes file content in chunks. OpenPGP mode currently loads the complete file and may require several times its size in free memory.
- File Safety: Authenticated decryption does not scan recovered content for malware and does not prove who sent it.
Enclave implements industry-standard cryptographic practices:
- XChaCha20-Poly1305 - authenticated symmetric encryption using Libsodium secret streams
- Argon2id - password-based key derivation using Libsodium's moderate limits for newly encrypted files
- OpenPGP.js - recipient-key encryption and decryption; the exact public-key algorithm comes from the supplied PGP key
- Implementation: Libsodium for password mode and OpenPGP.js for PGP mode
Read PRIVACY.md for the complete threat model, host metadata, ciphertext leakage, browser-memory caveats, and offline verification guidance. The dated findings and remediations from the repository review are recorded in SECURITY_AUDIT.md.
- Node.js 24
- pnpm 10
git clone https://github.com/hopeugetherpes/enclave.git
cd enclave
pnpm install --frozen-lockfile
pnpm devpnpm buildThe production build is a static export written to out/. It also creates a portable offline edition:
out/enclave.html— the complete application in one self-contained fileout/enclave.html.sha256— a SHA-256 checksum for verifying that file
The offline edition embeds its required CSS, JavaScript, Libsodium, and OpenPGP code. Its content-security policy blocks network connections, so it can be opened directly from disk without an internet connection. The hosted HTML receives a separate hash-based policy, while Vercel adds defense-in-depth security headers. The Save offline .html link in the website footer downloads the portable edition.
To regenerate only the portable file after pnpm build:web, run:
pnpm build:offlineEnclave is configured for a zero-configuration deployment from GitHub:
- In Vercel, choose Add New → Project.
- Import
https://github.com/hopeugetherpes/enclave. - Click Deploy without changing the detected settings.
The repository declares the Next.js framework, build command, static out/ directory, and Node.js version. Vercel automatically detects pnpm from pnpm-lock.yaml. No environment variables, server, database, or external service are required.