Your files.
Actually private.
Protect your files from hackers today and quantum computers tomorrow. Hybrid post-quantum encryption with client-held keys.
Cloud providers can read your files. Ex-employees might still have access.HybridCipher changes that.
The Quantum Threat Timeline
Your files encrypted today with standard encryption will be readable tomorrow.Nation-states are already collecting encrypted data to decrypt later. If your data has value beyond 5 years—personal photos, medical records, financial documents—you need quantum-resistant encryption now.
About HybridCipher
HybridCipher is a security-focused file encryption system exploring post-quantum cryptography, long-lived data confidentiality, and cryptographic access revocation.
Keys stay on user devices. The server cannot decrypt your files.
🚫What We Don't Do
- We don't store your encryption keys
Your keys live on your devices—never on our servers
- We don't process unencrypted file contents
All encryption happens client-side before upload
- We don't require internet for local decryption
Access your files offline once keys are synced
Why HybridCipher?
The only file encryption system built for both privacy-conscious individuals and security-demanding teams
Future-Proof Security
Protected for decades, not just years
- Post-quantum cryptography (ML-KEM-768) protects against both current and quantum computing threats
- Hybrid key delivery combines X25519 with ML-KEM-768 for classical and post-quantum coverage
- Zero-knowledge architecture: even the server can't read your files
Effortless Collaboration
Security without compromise
- Add or remove team members instantly—no key management headaches
- Automatic access control: current members decrypt files, removed members can't
- macOS beta available now, with broader desktop support planned
Zero Trust, Maximum Control
Your keys, your data, your control
- Your encryption keys never leave your devices
- Server is untrusted by design—all cryptography happens client-side
- Verifiable audit trails for membership and key events
Seamless Cryptographic Rekeying
Zero-downtime epoch transitions
- Zero-downtime migration—new epoch activates while old files migrate automatically in background
- Merkle-proven tracking ensures every file transitions to new epochs with transparency logs
- Policy-gated atomic cutover with coverage checks and rollback safeguards
How It Works
Client-side cryptography with a simple folder workflow
Drop your files
Just like any cloud drive—drag, drop, or save files directly to your HybridCipher folder.
No complex setup. No certificates. No key exchanges. Just use it.
Encrypted on your device
Files are encrypted on your device with hybrid quantum-resistant algorithms before they ever leave.
Using NIST-approved ML-KEM-768 + battle-tested X25519. Your encryption keys stay on your devices.
Store anywhere
Store encrypted files in any cloud folder you choose. Storage providers only see encrypted blobs.
Compatible with any cloud folder. No vendor lock-in. Complete privacy.
Share securely
For teams: invite members with one click. They get access. Remove them just as easily.
Automatic rekeying ensures removed members lose access to new encryption epochs.
Audit transparency
Cryptographic audit logs track membership and key events with Merkle commitments.
Audit tooling enables verification and transparency integration.
Choose Your Mode
Start with the available personal beta, or review the collaboration architecture that is coming next.
Personal
For private folders and individual file protection
- Apple Silicon macOS beta available now
- Client-side encryption before files reach cloud storage
- Hybrid post-quantum key protection with ML-KEM-768 + X25519
Collaboration
For group sharing, revocation, and auditability
- Group epochs for membership-aware key rotation
- Cryptographic revocation through rekeying, not policy alone
- Tamper-evident audit logs for membership and key events
Cryptographic Accountability
Most "encrypted" drives just promise security. HybridCipher proves it.
Built-in transparency logs
Merkle tree commitments create tamper-proof audit trails
Provable epoch transitions
Track when groups move to new encryption epochs
Out-of-band verification
Safety numbers and fingerprint pinning for extra trust
Audit tooling in development
Reporting workflows are in development
Own Your Privacy
We can't read your files. We can't change them. We can't see who has access. And we can prove it.
Use Any Cloud
Compatible with any cloud folder—use what you trust without trusting it
Open Source, Public
Our public repository is live on GitHub. No security through obscurity, no backdoors.
OPAQUE PAKE
Password authentication without ever sending your password to the server—mathematically proven secure
Security Engineering Practices
Ready to truly protect your files?
Start with the beta build, then inspect the cryptographic design behind it.