A small Windows tool to encrypt and decrypt a single file or an entire folder with a password.
- Encrypt: drag a file or folder onto
AegisCrypt.exe, or right-click it and choose Encrypt with AegisCrypt (after enabling Explorer integration once, from the app's home screen). Enter a password, confirm it, and the tool produces aname.aegisvault next to it; the original file/folder is securely overwritten and deleted. - Decrypt: double-click a
.aegisfile, or drag it ontoAegisCrypt.exe. Enter the password used to create it to restore the original file or folder; the vault is removed once decryption succeeds.
Passwords can be any length, including a single character - AegisCrypt doesn't second-guess your choice. When "Show password" is checked while encrypting, the confirmation field is skipped, since you can already see what you typed.
- Cipher: AES-256-GCM, streamed in 64 KiB authenticated chunks (the STREAM construction), so encrypting/decrypting a large file or folder never needs to hold the whole thing in memory, and chunks cannot be reordered, dropped, or spliced without detection.
- Key derivation: Argon2id (64 MiB, 3 passes) from the password and a random 16-byte salt stored in the vault. The salt is generated by the tool, not typed by the user - a second user-supplied "salt" doesn't add security over a longer password, only a way to lock yourself out.
- Folders are packed with a small internal streaming format (see
src/archive.rs) instead of a zip file: no compression (most of what people encrypt - photos, videos, archives - is incompressible anyway, so compressing it just burns CPU for nothing), and no temp file either - the folder is walked and its bytes flow straight into the cipher and back out again in a single pass. On a ~1 GiB test folder that's ~3 s to encrypt and ~2 s to decrypt on ordinary hardware (AES-NI does the heavy lifting); a 6 GiB folder is on the order of 15-20 s rather than several minutes. - File format: see the header comment in
src/crypto.rs. - A handful of OS-critical paths (
C:\Windows,C:\Program Files, the user's whole profile/AppData/Documents root, etc.) are refused as targets, except under Downloads/Desktop.
The window has a fixed size - it can't be resized, maximized, or snapped - since there's nothing on it that benefits from more room.
cargo build --release
The binary is written to target/release/AegisCrypt.exe and has no external
runtime dependencies. The app icon (assets/icon.ico, assets/icon_256.rgba)
was drawn procedurally rather than hand-made; swap those two files for real
artwork at the same resolutions if you'd rather use your own.
cargo test --release
Covers the encryption format (roundtrip, wrong password, tampering, truncation) and the end-to-end file/folder workflow, including that a failed decryption never touches the vault and a successful one always removes the plaintext original.