Skip to content

Repository files navigation

ZeeCrypt

ZeeCrypt is a very small, very simple, yet very secure encryption tool that you can use to protect your files. It's a Windows-only fork of Picocrypt, designed to be the go-to tool for file encryption, with a focus on security, simplicity, and reliability. ZeeCrypt uses the secure XChaCha20 cipher and the Argon2id key derivation function to provide a high level of security.

🚀 This repo is actively maintained. Unlike the original (now-archived) Picocrypt, ZeeCrypt is under active development — bug reports, feature requests, and suggestions are welcome, so feel free to open an issue. See CONTRIBUTING.md if you'd like to contribute code, and SECURITY.md to report a vulnerability.


ZeeCrypt

Downloads

ℹ️ You are highly recommended to read through the Features section below to fully understand the features and limitations of ZeeCrypt before using it. ℹ️

Make sure to only download ZeeCrypt from this repository. When sharing ZeeCrypt with others, be sure to link to this repository to prevent any confusion.

Windows

To download the latest, standalone, and portable executable for Windows, click here.

If you use ZeeCrypt frequently, you can also download the installer for Start Menu and Desktop shortcuts, automatic file extension association, and a right-click "Open with ZeeCrypt" entry in Explorer. This installs to Program Files, so it requires administrator privileges (a UAC prompt) during installation.

If your antivirus flags ZeeCrypt as a virus, please report it as a false positive to help everyone.

ZeeCrypt targets Windows 11 only; it is not built or tested for macOS or Linux.

Compatibility and upgrading

  • Upgrading to v2.0.0 from v1.50 or v1.51: volumes that use keyfiles can't be opened by v2.0.0 (a security fix changed how their header is authenticated). Decrypt them with your current version before upgrading, then re-encrypt with v2.0.0. Password-only volumes open normally.
  • Coming from Picocrypt: ZeeCrypt can't open volumes made by Picocrypt or by ZeeCrypt versions before 1.50. Decrypt them with the tool that created them, then re-encrypt with ZeeCrypt.
  • See the Changelog for everything that changed in each release.

Comparison

Here's how ZeeCrypt compares to other popular encryption tools.

ZeeCrypt VeraCrypt 7-Zip GUI BitLocker Cryptomator
Free ✅ Yes ✅ Yes ✅ Yes ✅ Bundled ✅ Yes
Open Source ✅ GPLv3 ✅ Multi ✅ LGPL ❌ No ✅ GPLv3
Cross-Platform ❌ Windows only ✅ Yes ❌ No ❌ No ✅ Yes
Size ✅ 3 MiB ❌ 20 MiB ✅ 2 MiB ✅ N/A ❌ 50 MiB
Portable ✅ Yes ✅ Yes ❌ No ✅ Yes ❌ No
Permissions ✅ None ❌ Admin ❌ Admin ❌ Admin ❌ Admin
Ease-Of-Use ✅ Easy ❌ Hard ✅ Easy ✅ Easy 🟧 Medium
Cipher ✅ XChaCha20 ✅ AES-256 ✅ AES-256 🟧 AES-128 ✅ AES-256
Key Derivation ✅ Argon2 🟧 PBKDF2 ❌ SHA-256 ❓ Unknown ✅ Scrypt
Data Integrity ✅ Always ❌ No ❌ No ❓ Unknown ✅ Always
Deniability ✅ Supported ✅ Supported ❌ No ❌ No ❌ No
Reed-Solomon ✅ Yes ❌ No ❌ No ❌ No ❌ No
Compression ✅ Yes ❌ No ✅ Yes ✅ Yes ❌ No
Telemetry ✅ None ✅ None ✅ None ❓ Unknown ✅ None

Keep in mind that while ZeeCrypt does most things better than other tools, it's not a one-size-fits-all and doesn't try to be. There are use cases such as full-disk encryption where VeraCrypt and BitLocker would be a better (and the only) choice. So while ZeeCrypt is a great choice for the majority of people doing file encryption on Windows, you should still do your own research and use what's best for you.

Features

ZeeCrypt is a very simple tool and most users will intuitively understand how to use it in a few seconds. On a basic level, simply dropping your files, entering a password, and hitting Encrypt is all that's needed to encrypt your files. Dropping the output back into ZeeCrypt, entering the password, and hitting Decrypt is all that's needed to decrypt those files. Pretty simple, right?

While being simple, ZeeCrypt also strives to be powerful in the hands of knowledgeable and advanced users. Thus, there are some additional options that you may use to suit your needs. Read through their descriptions carefully as some of them can be complex to use correctly.

  • Password generator: ZeeCrypt provides a secure password generator that you can use to create cryptographically secure passwords. You can customize the password length, as well as the types of characters to include.
  • Comments: Use this to store non-sensitive text along with the volume (it won't be encrypted and simply can't be by design). For example, you can put a description of the file you're encrypting before sending it to someone. When the person you sent it to drops the volume into ZeeCrypt, your description will be shown to that person. Or, if you're backing up personal files, you can give a description of the volume's contents so you can quickly remind yourself without having to fully decrypt. Since comments are neither encrypted nor authenticated, it can be freely read and modified by an attacker. Thus, it should only be used for non-sensitive, informational purposes in trusted environments.
  • Keyfiles: ZeeCrypt supports the use of keyfiles as an additional form of authentication (or the only form of authentication). Any file can be used as a keyfile, and a secure keyfile generator is provided for convenience. Not only can you use multiple keyfiles, but you can also require the correct order of keyfiles to be present for a successful decryption to occur. A particularly good use case of multiple keyfiles is creating a shared volume, where each person holds a keyfile, and all of them (and their keyfiles) must be present to decrypt the shared volume. By checking the "Require correct order" box and dropping your keyfile in last, you can also ensure that you'll always be the one clicking the Decrypt button. Use the keyfile generator whenever possible for the best security.
  • Paranoid mode: Using this mode will encrypt your data with both XChaCha20 and Serpent in a cascade fashion, and use HMAC-SHA3 to authenticate data instead of BLAKE2b. Argon2 parameters will be increased significantly as well. This is recommended for protecting top-secret files and provides the highest level of practical security attainable. For a hacker to break into your encrypted data, both the XChaCha20 cipher and the Serpent cipher must be broken, assuming you've chosen a good password. It's safe to say that in this mode, your files are impossible to crack. Keep in mind, however, that this mode is slower and isn't really necessary unless you're a government agent with classified data or a whistleblower under threat.
  • Reed-Solomon: This feature is very useful if you are planning to archive important data on a cloud provider or external medium for a long time. If checked, ZeeCrypt will use the Reed-Solomon error correction code to add 8 extra bytes for every 128 bytes of data to prevent file corruption. This means that up to ~3% of your file can corrupt and ZeeCrypt will still be able to correct the errors and decrypt your files with no corruption. Of course, if your file corrupts very badly (e.g., you dropped your hard drive), ZeeCrypt won't be able to fully recover your files, but it will try its best to recover what it can. Note that this option will slow down encryption and decryption speeds significantly.
  • Force decrypt: ZeeCrypt automatically checks for file integrity upon decryption. If the file has been modified or is corrupted, ZeeCrypt will automatically delete the output for the user's safety. If you would like to override these safeguards, check this option. Also, if this option is checked and the Reed-Solomon feature was used on the encrypted volume, ZeeCrypt will attempt to recover as much of the file as possible during decryption.
  • Split into chunks: Don't feel like dealing with gargantuan files? No worries! With ZeeCrypt, you can choose to split your output file into custom-sized chunks, so large files can become more manageable and easier to upload to cloud providers. Simply choose a unit (KiB, MiB, GiB, or TiB) and enter your desired chunk size for that unit. To decrypt the chunks, simply drag one of them into ZeeCrypt and the chunks will be automatically recombined during decryption.
  • Compress files: By default, ZeeCrypt uses a zip file with no compression to quickly merge files together when encrypting multiple files. If you would like to compress these files, however, simply check this box and the standard Deflate compression algorithm will be applied during encryption.
  • Deniability: ZeeCrypt volumes typically follow an easily recognizable header format. However, if you want to hide the fact that you are encrypting your files, enabling this option will provide you with plausible deniability. The output volume will be indistinguishable from a stream of random bytes, and no one can prove it is a volume without the correct password. This can be useful in an authoritarian country where the only way to transport your files safely is if they don't "exist" in the first place. Keep in mind that this mode slows down encryption and decryption speeds, requires you to manually rename the volume afterward, renders comments useless, and also voids the extra security precautions of the paranoid mode, so you should only use it if absolutely necessary. If you've never heard of plausible deniability, this feature is not for you.
  • Recursively: If you want to encrypt and/or decrypt a large set of files individually, this option will tell ZeeCrypt to go through every recursive file that you drop in and encrypt/decrypt it separately. This is useful, for example, if you are encrypting thousands of large documents and want to be able to decrypt any one of them in particular without having to download and decrypt the entire set of documents. Keep in mind that this is a very complex feature that should only be used if you know what you are doing.
  • Explorer integration: If you installed ZeeCrypt with the MSI installer, right-clicking a file or folder shows an "Open with ZeeCrypt" entry. ZeeCrypt automatically detects whether to encrypt or decrypt based on what you open, so there's no separate Encrypt/Decrypt option to pick - just right-click and go. Selecting multiple files or folders and right-clicking opens them all in one window.
  • Update checker: Click the version number at the bottom-right of the window to check for a new release. Nothing happens automatically - checking only happens when you click, and if an update is found, you'll see the release notes with an "Update Now" button rather than anything downloading or installing on its own. The downloaded update is verified against its published checksum before it replaces the running executable.

Security

For more information on how ZeeCrypt handles cryptography, see Internals for the technical details. ZeeCrypt is a fork of Picocrypt, which was independently audited before this fork's changes were made; ZeeCrypt itself has not yet been separately audited, so treat its Windows-only changes accordingly.

ZeeCrypt operates under the assumption that the host machine it is running on is safe and trusted. If that is not the case, no piece of software will be secure, and you will have much bigger problems to worry about. As such, ZeeCrypt is designed for the offline security of volumes and does not attempt to protect against side-channel analysis.

One finding from the original Picocrypt audit is still open: PCC-004 (decrypt-then-verify). Integrity is checked after decryption rather than before, but output is written to a temporary .incomplete file that is deleted if the check fails, so tampered data is never left behind as a finished file. See Internals for details.

ZeeCrypt makes no network requests on its own. The only exception is the update checker (bottom-right of the window), which only runs when you click it — it queries the GitHub Releases API and, if you choose to install an update, verifies its SHA-256 checksum before replacing the running executable. Nothing is ever downloaded or applied without you explicitly clicking to do so.

FAQ

Does the "Delete files" feature shred files?

No, it doesn't shred any files and just deletes them as your file manager would. On modern storage mediums like SSDs, there is no such thing as shredding a file since wear leveling makes it impossible to overwrite a particular sector. Thus, to prevent giving users a false sense of security, ZeeCrypt doesn't include any shredding features at all.

Is ZeeCrypt quantum-secure?

Yes, ZeeCrypt is secure against quantum computers. All of the cryptography used in ZeeCrypt works off of a private key, and private-key cryptography is considered to be resistant against all current and future developments, including quantum computers.

License

This project is licensed under GPL-3.0-only, as a fork of Picocrypt (also GPL-3.0-only).

About

Small, portable Windows file encryption tool. XChaCha20 + Argon2id with optional Serpent cascade (paranoid mode), keyfiles, Reed-Solomon error correction, plausible deniability, and file splitting. Actively maintained fork of Picocrypt. GPL-3.0.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages