New here? Start with : it creates your private key file and the public key file you give to others.
Encryption and decryption happen locally in your browser. Your file never leaves your device.
Files, keys and identities are the same across the Web Vault and the native macOS and Windows applications: a file protected in one unlocks in the others.
Generate Identity
Your identity is generated on this device. Aexa never receives it. You will download two files: a private key file you keep, and a public key file you can send to anyone who needs to protect a file for you.
If you forget this passphrase, your key cannot be recovered — not by you, and not by Aexa. Every file protected for this key becomes permanently unreadable. There is no reset.
Your identity is ready
Your fingerprint
Share this fingerprint with people who send you files, using a channel other than the one that carries your public key file — a phone call, a video call, or in person. It is how they confirm the key they received is really yours.
Keep two copies of the private key file in different places, store the passphrase separately, and try unlocking it once before you rely on it.
Protect a file
-
1 Recipient key
Drop
.aexpubor choose a file
Recipient fingerprint
Anyone who can intercept the key file you were sent can also replace the key inside it. Confirming the fingerprint on a different channel is what stops that.
-
2 File
Drag your file here
or choose a file · up to 100 MB in this beta
Your file stays on this device.
-
3 Protect
Add a recipient key, confirm its fingerprint, and choose a file.
Encrypting locally. No file data is being sent to Aexa.
- Preparing file locally
- Encrypting file with AES-256
- Protecting the encryption key with NIST ML-KEM (FIPS 203)
- Creating your secure .aex file
Your protected file is ready.
Your original file never left your device.
Optional integrity check
If you read this checksum to the recipient over a channel you trust, they can compare it after unlocking to confirm the file is exactly what you sent. This beta does not sign files, so this comparison is the only way to confirm who a file came from.
Unlock a file
-
1 Protected file
Drag your
.aexfile hereor choose a file
-
2 Your private key
Drop your
.aexkeyor choose a file
-
3 Unlock
Decrypting locally. No file data is being sent to Aexa.
- Checking your keys
- Unlocking the post-quantum protected key
- Decrypting locally
- Verifying integrity
Original file ready.
Aexa cannot tell you who sent this file. Anyone who has your public key can create a file that opens with your key. Only open files you were expecting, from someone you can verify another way.
Optional integrity check
If the sender read you a checksum over a channel you trust, compare it now. If it matches, this file is exactly what they sent.