Runs the same crypto as the desktop app — no server, no upload. Everything happens right here, in this browser, via the Web Crypto API.
Pick any file and a passphrase. The passphrase is stretched into a 256-bit key with PBKDF2, then used to encrypt the file with AES-256-GCM. A random salt and IV are generated per file — nothing is reused.
Upload the .enc file produced above and re-enter the passphrase. GCM's authentication tag means a wrong passphrase or a tampered file fails loudly instead of silently returning garbage.
In the full system, the AES key itself is wrapped with a 2048-bit RSA public key so it can be shared without ever transmitting the passphrase. This step generates a fresh RSA keypair in your browser and wraps a random 256-bit key with it, then unwraps it with the private key to prove round-trip correctness.