ZMath● All processing stays in this browser

INDEPENDENT • SELF HOSTED • NO ACCOUNT

Your files.
Your keys. Your control.

Protect a file or message using conventional authenticated encryption. No main node, subscription, API key or company server is needed.

Open Dual Key — notes & attachment vault →

1. Set your recovery factors

Keep the passphrase and any factor files safely. There is no password reset.

If selected during encryption, the exact same file is required to decrypt.

Advanced: optional external factor

This is an additional local secret input, not quantum encryption or verified hardware evidence. An existing ZQF1 factor file can be imported for compatibility. Its self-reported source is not attestation.

2. Choose an operation

Plaintext limit: 50 MiB. JSON container limit: 72 MiB. Older server-bound Portable/Exclusive envelopes use a different format and are not opened here.

Ready. Save your recovery factors before encrypting.

Standard primitives

AES-256-GCM, PBKDF2-HMAC-SHA-256 and HKDF-SHA-256. The preserved implementation authenticates its canonical header and rejects a wrong key or altered container.

Visible metadata

The filename, size, timestamp, algorithms and optional factor commitment remain visible. The encrypted content stays confidential only while your keys and device remain secure.

Preserved and reviewable

The cryptographic snapshot is unchanged from the source evaluated in the August 2026 ZME1 paper. This is research software; regression checks are not an independent security audit.