File encryption privacy ratings
Tools that encrypt files and drives.
12 file encryption are rated against 4 public criteria, and 12 have enough evidence for a letter grade. Of the 4 with a known jurisdiction, 2 are based in a Five Eyes country, and 3 in the wider Fourteen Eyes.
Open-source file encryption only · Criteria for this category · Suggest an addition · Markdown
| Name | Grade | Score | Data | Jurisdiction | Open source | No trackers or telemetry | No ads or data sales | Independent audit |
|---|---|---|---|---|---|---|---|---|
Small open source file encryption tool for desktop that uses XChaCha20 and Argon2id, with optional keyfiles, Reed-Solomon error correction and plausible deniability. The original project is archived and no longer developed. |
Grade A | 100 | 100% | – | Yes | Yes | Yes | Yes |
Open source encrypted overlay filesystem that runs as a FUSE mount and stores each file as a separate encrypted file, suited to cloud-synced folders. Also has a reverse mode for encrypted backups. |
Grade A | 90 | 100% | – | Yes | Yes | Yes | Partial |
Open source disk encryption for Windows, macOS and Linux. Creates encrypted file containers or encrypts whole partitions and system drives, and supports hidden volumes. |
Grade A | 90 | 100% | Japan Outside Eyes | Yes | Yes | Yes | Partial |
Open source file archiver with its own 7z format that can encrypt 7z and ZIP archives with AES-256, including file names in 7z archives. The full graphical app is for Windows, with a command-line version for Linux and macOS. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
Cross-platform file encryption tool that encrypts individual files with AES-256 using a password or key file. Available as a desktop app, command-line tool and Android app. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
Command-line file encryption tool and Go library that uses small explicit keys, has no config options and works with standard Unix pipes. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
Command-line utility for setting up Linux disk encryption with the dm-crypt kernel module. Supports LUKS, plain dm-crypt, TrueCrypt, VeraCrypt, BitLocker and FileVault2 volumes. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
Client-side encryption for files stored in cloud services. Encrypts each file separately inside a vault so the files can sync individually. Available for desktop, Android and iOS. |
Grade B | 75 | 100% | Germany Fourteen Eyes | Yes | Partial | Yes | Partial |
Open source command-line tool for encrypting and signing files with a passphrase, symmetric key or public keys, using modern primitives with no configuration options. |
Grade C | 65 | 100% | – | Yes | Partial | Yes | No |
Full-disk encryption built into macOS that encrypts the startup volume with XTS-AES-128. The recovery key can be kept locally or escrowed with an iCloud account or a device management server. |
Grade D | 45 | 100% | United States Five Eyes | No | Partial | Yes | Partial |
Open source partition and full-disk encryption for Windows, including system drives on UEFI/GPT machines. |
Grade F | 30 | 100% | – | Yes | No | No | No |
Full-volume encryption built into Windows Pro, Enterprise and Education editions. Protects fixed and removable drives, typically using the device TPM to hold keys. |
Grade F | 20 | 100% | United States Five Eyes | No | No | Yes | No |
Questions
What is the most private option among file encryption?
No pick has been made yet. The table above is sorted by score, based on public evidence.
How are file encryption rated?
Each entry answers 4 questions: open source, no trackers or telemetry, no ads or data sales and independent audit. Answers need links to evidence. See the full criteria.
Does jurisdiction matter?
Jurisdiction decides which laws can compel a provider to hand over data. Each entry shows its country and whether it is in the Five, Nine or Fourteen Eyes. The data a provider can hand over depends mostly on what it stores and who holds the keys. Read about jurisdictions and the CLOUD Act.