A feature of LMN8

Unreadable to everyone, except you.

Encrypt turns a folder into a secure vault on the device it already lives on. Nothing is uploaded. Nine cipher suites to choose from, including post-quantum, and a key derived on your device that we never see.

secured
Cipher suite
AES-256-GCM
Military-grade encryption — recommended
XChaCha20-Poly1305
Extended-nonce ChaCha for large files
Triple-Layer Hybrid
AES-256 → ChaCha20 → XChaCha20, stacked
ML-KEM-1024 HybridPQ
Post-quantum KEM (FIPS 203) + AES-256
Personal vault
12 files · AES-256-GCM
67169e0684fb34dab685f18a70221e098dde1dd614939ba79a2f1ecc15c26290
Client contracts
47 files · Triple-Layer Hybrid
11c32ea5fa5b8d3fea43ac8a8672e29e9b1695bb3a4955c6b12565344599e1f5
Journal
3 files · open
Nine cipher suites · post-quantum ready · keys never leave your device.
Using Encrypt

Protect, in three calm steps.

Encrypt is built so the private option is always the easy one — no manuals required.

1
Choose a folder

Turn any folder into a sealed vault on your device. Nothing is uploaded.

2
Pick a cipher suite

One of nine AEAD suites — or stack three in a triple-hybrid for defense in depth.

3
Set smart passwords

Up to three: one opens the real vault, one a decoy, one quietly destroys it.

Smart encryption

One vault. Three passwords.

Set up to three passwords for the same vault. Which one you type decides what happens — so a forced unlock never has to reveal what actually matters.

Password 1
Read

Your real password. Opens the vault and shows your files, exactly as you left them.

Password 2
Decoy

Opens a believable decoy folder you set up in advance. Plausible deniability when someone’s watching.

Password 3
Destroy

Looks like a normal unlock, but silently runs a Zero wipe of the vault. The wrong hands become a kill switch.

What Encrypt does

Your files. Your keys.

/01
On-device vaults

Encrypt folders on the device they already live on. Nothing is uploaded.

/02
Nine cipher suites

AES-256-GCM, ChaCha20-Poly1305, XChaCha20, AES-GCM-SIV, a combined AEAD mode, a compressed AES variant, and two post-quantum hybrids.

/03
Triple-layer hybrid

Stack AES, ChaCha20, and XChaCha20 in one pass when you want belt, braces, and a spare.

/04
Keys we never see

Derived on your device with Argon2id (64 MB, memory-hard). Nothing to escrow, sync, or hand over.

/05
Contents stay private

File contents, extensions, and structure are sealed under encryption. An adversary sees an opaque container.

/06
Post-quantum, available

ML-KEM-768 and ML-KEM-1024 hybrids (FIPS 203) ship today, so your vaults stay sealed against tomorrow’s computers.

Availability

Wherever your data lives.

Encrypt comes with LMN8 — one account that reaches every device you own.

Windows○ Coming soon
Android○ Coming soon
macOS○ Coming soon
iOS○ Coming soon
Questions

More about Encrypt.

You can set up to three passwords for one vault. The Read password opens the real files, the Decoy password opens a harmless folder you set up in advance, and the Destroy password silently runs a Zero wipe of the vault.

Because keys are derived on your device and never escrowed, we can’t reset it for you — that’s what makes it secure. Set up a recovery option when you create a vault.

Yes — nine AEAD cipher suites including AES-256-GCM, ChaCha20-Poly1305, and two post-quantum ML-KEM hybrids, with Argon2id key derivation. Stack three in a triple-hybrid for the most sensitive vaults.

Your files. Your keys.

Encrypt — Lock files on your device | LMN8