AES-256-GCM Encryption
LockBytes uses AES-256-GCM authenticated encryption to protect encrypted file data and help detect unauthorized modification.
LockBytes is a Windows desktop application designed to protect sensitive files using strong encryption and a registered USB storage device.
Your files remain under your control. LockBytes operates locally by default, while optional Google Drive recovery can help protect your encrypted vault against data loss.
LockBytes is built around a simple idea: sensitive files should remain under the user's control.
LockBytes is a Windows desktop application that allows users to create a protected vault, encrypt files, and unlock protected data using a registered USB storage device and secure passwords.
The application is designed to operate locally. An internet connection is not required for normal encryption and decryption operations.
An optional Google Drive recovery feature is available for users who want an additional copy of their encrypted recovery data. This feature is user-controlled and uses the user's own Google account.
LockBytes combines strong encryption with device-bound access and a local-first design.
LockBytes uses AES-256-GCM authenticated encryption to protect encrypted file data and help detect unauthorized modification.
A registered USB storage device is used as part of the vault protection process, adding a physical component to access control.
The vault is protected using dedicated credentials and modern key derivation techniques designed to protect encryption keys.
LockBytes uses chunk-based processing so that large files can be encrypted without requiring the entire file to be loaded into memory at once.
Normal file encryption and decryption are performed locally. Your files do not need to be uploaded to a LockBytes server.
Users can optionally connect their own Google Drive account to store encrypted recovery and synchronization data.
LockBytes keeps the normal workflow local while combining software credentials with a registered USB device.
Register a USB storage device with your LockBytes vault.
Create your vault credentials and establish the cryptographic protection used by the application.
Select files and protect them using authenticated encryption.
Connect the registered USB device and provide the required credentials to access protected data.
LockBytes can optionally use Google Drive to help protect against the loss of important recovery data.
This feature is completely optional. LockBytes does not require Google Drive for normal encryption and decryption.
LockBytes is not designed as a cloud storage service. The application performs its core encryption and decryption operations on the user's computer.
The optional recovery system exists to help users maintain encrypted recovery information, rather than to replace local file protection.
LockBytes is designed as a local-first desktop application. Your files are not uploaded to a LockBytes server for normal operation.
When you choose to use Google Drive recovery, Google handles the associated account and Drive services under Google's own policies.
Download LockBytes from the official GitHub repository and protect your sensitive files locally.