A private-by-design DrawSplat Tool
A silver digital shield protecting a luminous blue data core

Your data.
Your keys. Your rules.

Lock sensitive files and text with authenticated AES-256 encryption—entirely inside your browser. Nothing is uploaded. Nothing is tracked.

256BIT ENCRYPTION
0BYTES UPLOADED
100%CLIENT-SIDE
SECURE WORKSPACE

What are we protecting?

Your browser becomes the vault. Choose a mode and your data never leaves this device.

Drop files or a folder into the vault recursive paths are detected automatically
ENTER A PASSWORD

Your password cannot be recovered. Store it safely and test decryption before deleting the original.

VERIFIABLE PROTECTION

Built like a vault.
Open like a window.

Modern browser cryptography with clear, inspectable guarantees. No mystery server and no account required.

ENCRYPTION ENGINE

AES-256-GCM

A modern authenticated cipher that protects confidentiality and detects changes or incorrect passwords before releasing data.

KEY SIZE 256 bitNONCE 96 bitAUTH TAG 128 bit

Password hardened

PBKDF2-SHA-256 stretches every password through 600,000 rounds with a unique 128-bit salt.

✓ SECURITY PROPERTY

Zero-knowledge flow

Files, text, passwords, and keys stay in browser memory. The app contains no upload code.

✓ LOCAL BY DESIGN

Tamper detection

GCM authentication rejects altered ciphertext and incorrect passwords without exposing partial content.

✓ INTEGRITY CHECKED
SECURITY OVERVIEW

Exact claims. Clear limits.

CipherSplat has one deployment mode: local browser processing. It has no Google, MySQL, hosted-vault, account, sync, upload, analytics, or tracking mode.

Password packages
AES-256-GCM; PBKDF2-HMAC-SHA-256 with 600,000 rounds and a fresh 128-bit salt.
File package format
CS2 records use a random 64-bit IV prefix, monotonic 32-bit counter, 96-bit GCM IV, 128-bit tag, and counter-bound additional data.
OpenPGP option
OpenPGP.js 6.3.1 is pinned and served locally. Encryption follows the recipient key's supported algorithm preferences; keys are never uploaded or persisted.
Key lifetime
Derived AES keys exist only inside the active operation. Passwords, imported keys, source text, and selected-file references clear after each result; downloadable results clear after 10 idle minutes.
Application storage
No cookies, localStorage, sessionStorage, IndexedDB, service API, or server database is used by CipherSplat.
Supply chain
No remote scripts, fonts, or cryptographic services. A strict CSP blocks connections and inline code; published SHA-256 hashes cover shipped code and assets.
1Your inputFile, folder, text, password, or key
2Browser memoryWeb Crypto or pinned OpenPGP.js
3Your downloadAuthenticated package or restored data

Network boundary: no application data crosses it. The downloaded edition's connection switch controls optional website links only.

PROTECTS AGAINST

Designed security boundary

  • Network interception and server-side data breaches
  • Package tampering and incorrect passwords
  • Path traversal during folder restoration
  • Accidental persistence by the application
OUT OF SCOPE

Device trust still matters

  • Malicious extensions, injected scripts, or a compromised browser
  • Keyloggers, screen capture, OS malware, or device administrators
  • Someone with access while this tab is unlocked
  • A modified offline copy or replaced production files
ASSURANCE STATUS

No borrowed trust claims

CipherSplat has automated functional checks and public source, but no current independent audit, SOC 2 attestation, paid bug bounty, or formal certification. Those are not implied by the security badges.

THREE STEPS. ONE PRIVATE RESULT.

How the vault works

01

Choose your data

Drop a file or paste text. It stays on your device.

02

Create the key

Your password and random salt derive a one-time vault key.

03

Lock & save

AES-GCM encrypts and authenticates your data for download.

LOCAL PASSWORD LAB

Create a vault password

Generated only on this device with cryptographically secure randomness. CipherSplat never stores or sends it.

Password type
Password strength: StrongEstimated entropy: