Local File Encryptor

Encrypt one local file into a password-protected .uftenc container and restore it with the same password.

Files stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Process file controls

Drop your file here

or choose one from your device

One file

    Encryption needs at least 12 characters. Keep a separate copy; there is no password recovery.

    Required when encrypting; ignored when decrypting.

    How to use Local File Encryptor

    1. Choose a local file and select Encrypt to .uftenc.
    2. Enter a password of at least 12 characters and repeat it in Confirm password.
    3. Download the encrypted container and keep the password separately.
    4. Test Decrypt with that container and password, then compare the restored file before discarding any copy.

    Example: Local File Encryptor

    Check an encrypt/decrypt round trip using non-sensitive bytes.

    You add
    Source filename: fixture.txt; UTF-8 contents: Hello . Encrypt using synthetic-long-password in both password fields. Then select Decrypt and provide the resulting fixture.txt.uftenc with the same password.
    You get
    Decryption restores fixture.txt containing exactly the six bytes 48 65 6c 6c 6f 0a. The encrypted bytes vary between runs because a fresh salt and IV are used.

    Options

    Operation
    Encrypt writes the project’s UFTENC01 container. Decrypt accepts that container and authenticates it before restoring its saved basename and content.
    Password
    Use a strong password kept outside the encrypted file. Encryption requires at least 12 characters; forgetting it leaves no recovery route.
    Confirm password for encryption
    Confirmation catches a typing difference when encrypting. It is ignored during decryption, which requires the original password.

    Supported inputs and limits

    Plain files up to 10 MiB. Custom UFTENC01 container using AES-256-GCM and PBKDF2-SHA-256 at 600,000 iterations with a random salt and nonce. Encryption needs at least 12 password characters and confirmation. This is not encrypted ZIP and has no password recovery. Keep a safe original until you test recovery. Native key derivation may finish after Cancel; another job waits until it settles.

    Where your input is processed

    This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

    The container is specific to this tool

    The file format combines password-derived encryption with stored file information. It is not a ZIP archive or a standard interchangeable encrypted document. Keep access to a compatible copy of the tool and prove a round trip before relying on the container for storage. The download does not conceal that an encrypted file exists.

    Authentication failures should stop recovery attempts

    A wrong password or altered container causes decryption to fail; a partial plaintext download is not produced. Do not interpret that failure as a diagnosis of which byte changed. Password strength, trusted-device security and keeping backups still matter. This tool has no independent security certification or password-recovery service.

    Questions about Local File Encryptor

    Can a ZIP app open the encrypted file?

    No. The custom .uftenc format is restored through this tool.

    Can a forgotten password be recovered?

    No. Store the password safely and test recovery before relying on the file.

    Does Cancel immediately stop key derivation?

    No. Native browser cryptography can finish in the background; the tool blocks another job until it settles.

    Project manager: Tony Hines · Content updated 3 October 2026 · Report a problem