Windows • Local-first • Privacy-focused

Your files. Your protection.

LockBytes is a Windows desktop application designed to protect sensitive files using strong encryption and a registered USB storage device.

Your files remain under your control. LockBytes operates locally by default, while optional Google Drive recovery can help protect your encrypted vault against data loss.

Designed for Windows 10 and Windows 11
LOCKBYTES
VAULT PROTECTED AES-256-GCM
USB DEVICE REGISTERED
ENCRYPTION AES-256-GCM
OPERATION LOCAL
RECOVERY OPTIONAL
AES-256-GCM Authenticated encryption
USB-BOUND Registered device protection
LOCAL-FIRST Works without the internet
OPTIONAL RECOVERY Your own Google Drive

Security without giving up control.

LockBytes is built around a simple idea: sensitive files should remain under the user's control.

LockBytes is a Windows desktop application that allows users to create a protected vault, encrypt files, and unlock protected data using a registered USB storage device and secure passwords.

The application is designed to operate locally. An internet connection is not required for normal encryption and decryption operations.

An optional Google Drive recovery feature is available for users who want an additional copy of their encrypted recovery data. This feature is user-controlled and uses the user's own Google account.

Built around practical security.

LockBytes combines strong encryption with device-bound access and a local-first design.

01

AES-256-GCM Encryption

LockBytes uses AES-256-GCM authenticated encryption to protect encrypted file data and help detect unauthorized modification.

02

USB-Bound Protection

A registered USB storage device is used as part of the vault protection process, adding a physical component to access control.

03

Password-Protected Vault

The vault is protected using dedicated credentials and modern key derivation techniques designed to protect encryption keys.

04

Large File Support

LockBytes uses chunk-based processing so that large files can be encrypted without requiring the entire file to be loaded into memory at once.

05

Local-First Operation

Normal file encryption and decryption are performed locally. Your files do not need to be uploaded to a LockBytes server.

06

Optional Recovery

Users can optionally connect their own Google Drive account to store encrypted recovery and synchronization data.

Protection built in simple steps.

LockBytes keeps the normal workflow local while combining software credentials with a registered USB device.

01

Register your USB

Register a USB storage device with your LockBytes vault.

02

Protect your vault

Create your vault credentials and establish the cryptographic protection used by the application.

03

Encrypt your files

Select files and protect them using authenticated encryption.

04

Unlock when needed

Connect the registered USB device and provide the required credentials to access protected data.

Your Google Drive. Your account. Your choice.

LockBytes can optionally use Google Drive to help protect against the loss of important recovery data.

This feature is completely optional. LockBytes does not require Google Drive for normal encryption and decryption.

  • Uses the user's own Google account
  • Uses the Google Drive API
  • Designed to work with LockBytes recovery data
  • Does not require access to unrelated Drive files
  • Can be skipped completely
Read how Google data is handled →
G
Google Drive Recovery Optional feature
LOCKBYTES_RECOVERY Encrypted recovery data
Access App-created files
Account Your Google Account
Required? No

Designed to keep sensitive data local.

LockBytes is not designed as a cloud storage service. The application performs its core encryption and decryption operations on the user's computer.

The optional recovery system exists to help users maintain encrypted recovery information, rather than to replace local file protection.

File encryption Local
Normal operation Offline
Encryption AES-256-GCM
Cloud recovery Optional
Cloud provider User's Google Drive
LockBytes file server None

No unnecessary cloud dependency.

LockBytes is designed as a local-first desktop application. Your files are not uploaded to a LockBytes server for normal operation.

When you choose to use Google Drive recovery, Google handles the associated account and Drive services under Google's own policies.

Ready for Windows.

Windows Windows 10 / Windows 11
Storage USB storage device
Internet Only for optional recovery/sync and update checks
Account Google account only if recovery is enabled

Take control of your files.

Download LockBytes from the official GitHub repository and protect your sensitive files locally.

Download from GitHub