Skip to content

Cryptomator

Client-side encryption for cloud files, with zero-knowledge privacy.

Self-hostedNot yet verified
Report issueDemo online
MIT★ 12000

Open the official app on cryptomator.org

This tool is hosted by its maintainers. Click below to open cryptomator.org in a new tab — it's their official demo.

Browse encryption tools →

What's next with Cryptomator?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Cryptomator?

Cryptomator is an open-source tool designed to enhance data security by providing client-side encryption for cloud storage. It enables users to protect their data by encrypting files and filenames using AES-256 encryption, ensuring that only the user holds the decryption keys. This addresses the common vulnerability of cloud providers encrypting data only during transmission or retaining decryption keys, which could be compromised. The tool is ideal for individuals and organizations prioritizing privacy, particularly those storing sensitive information like personal documents, financial records, or business data. By offering integration across devices, Cryptomator bridges the gap between cloud accessibility and data sovereignty, users to maintain control over their information without complex configurations. The primary problem Cryptomator solves is the lack of user control over data encryption in cloud storage. Most services encrypt data in transit but not at rest, leaving files vulnerable if the provider’s infrastructure is breached. Cryptomator mitigates this risk by encrypting data locally before it reaches the cloud, ensuring that even if the cloud provider’s servers are compromised, the encrypted files remain inaccessible without the user’s password. Its simplicity and cross-platform support make it accessible to non-technical users, while its open-source nature allows for transparency and community-driven improvements. This positions Cryptomator as a critical tool for anyone seeking to safeguard their digital assets against both external threats and potential misuse of cloud provider infrastructure.

How it works

Cryptomator is a free, open-source application that encrypts data locally before it is uploaded to cloud storage services. Its primary purpose is to grant users full control over their data encryption keys, ensuring that only the user can access their files. This contrasts with cloud providers that typically manage encryption keys, creating a potential security risk if those keys are compromised. By encrypting files and filenames with AES-256 encryption, Cryptomator ensures that even if cloud storage is accessed without authorization, the data remains unreadable. This makes it particularly valuable for users concerned about privacy, including journalists, activists, and businesses handling confidential information. Cryptomator allows users to create encrypted 'vaults' within their cloud storage by assigning a password to a folder. These vaults function as virtual encrypted drives, enabling file management across devices. The tool supports major cloud platforms like Dropbox, Google Drive, and OneDrive, with no registration or configuration required beyond setting a password.

How to use it

  1. 1Install Cryptomator on your device from the official website or package repositories. 2. Connect to your cloud storage service (e.g., Dropbox, Google Drive) through the application. 3. Select a folder in your cloud storage and create a new vault by setting a password. 4. Access the vault by entering the password, which will mount it as an encrypted drive for file management. Practical tips include using a strong, unique password for each vault and enabling backup options for the password. Avoid storing the password in insecure locations, and ensure your cloud storage provider supports the necessary integration protocols.

What it can do

  • cloud encryption

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/cryptomator/cryptomator
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Users must manually manage encryption keys, which requires remembering passwords for each vault.
  • Encrypted files cannot be directly accessed by cloud storage providers, limiting certain advanced features.
  • The tool relies on third-party cloud services for storage, which may introduce dependency risks.
  • No built-in synchronization features between vaults, requiring manual file management.
  • Performance may degrade with extremely large datasets due to local encryption overhead.

Understanding the result

Client-side encryption for cloud files, with zero-knowledge privacy.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(cryptomator/cryptomator)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with cryptomator/cryptomator. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Cryptomator and how does it differ from cloud storage encryption?

Cryptomator is a client-side encryption tool that encrypts data locally before uploading to cloud storage, ensuring users retain control of encryption keys. Unlike many cloud providers that encrypt data in transit but not at rest, Cryptomator encrypts files and filenames using AES-256, making them inaccessible even if the cloud provider’s servers are compromised. This contrasts with services like Dropbox or Google Drive, which typically manage encryption keys centrally.

How does Cryptomator ensure data remains secure during uploads?

Cryptomator encrypts files and filenames locally using AES-256 encryption before they are uploaded to the cloud. This means the data is already protected when it leaves the user’s device, and the cloud provider cannot access the encrypted content. The encryption process occurs entirely on the user’s machine, with no intermediate steps involving unencrypted data. The resulting encrypted files are stored in the cloud, but they remain unreadable without the user’s password.

How do I set up a vault in Cryptomator?

To create a vault, first install Cryptomator and connect it to your cloud storage service. Navigate to the cloud folder where you want to store encrypted data, then select 'Create Vault' and set a password. This password will be used to unlock the vault across all devices. Once created, the vault appears as an encrypted drive, allowing you to drag and drop files as if it were a local folder. Ensure the password is stored securely, as recovery is not possible if lost.

How does Cryptomator compare to alternatives like Veracrypt or Tresorit?

Cryptomator focuses on cloud storage encryption, integrating seamlessly with services like Dropbox and Google Drive, while Veracrypt is a standalone disk encryption tool for local drives. Tresorit offers end-to-end encryption for cloud storage but requires a subscription and does not support open-source development. Cryptomator’s advantage lies in its simplicity and open-source transparency, whereas Tresorit provides managed encryption without user configuration. Veracrypt, while more flexible, lacks direct cloud integration.

What should I do if I forget my vault password?

If you forget your vault password, Cryptomator cannot recover it. The password is required to decrypt the vault, and there are no backup mechanisms for lost passwords. To prevent this, store the password securely in a password manager or physical safe. If the vault is critical, consider using a password recovery tool compatible with Cryptomator’s encryption format, though this is not officially supported and may not work reliably.

Spotted something wrong with Cryptomator, or want to maintain it? See how to help.