Transparent encryption for files that live in the cloud
Cryptomator creates an encrypted vault inside a folder you already have, then presents that vault as a normal drive. The cloud client keeps synchronising the folder, but what it uploads is ciphertext: file names, folder structure and contents are all encrypted before they leave the machine. That makes it possible to keep using Dropbox, Google Drive, OneDrive or a plain network share while denying the provider readable access to the material inside the vault.
What a vault is and how it is unlocked
A vault is a directory containing an encrypted file tree plus a small vault configuration file. You pick a passphrase when the vault is created, and the application derives the keys from it. Several vaults can be unlocked side by side, each with its own passphrase, which is useful for separating work, personal and archive material. Once unlocked, the vault appears as a drive letter and behaves like any other disk: applications open, save and rename files without knowing that encryption is happening underneath. Where a vault is locked, the encrypted files remain visible in the folder but are meaningless without the passphrase. Newer versions can also create a recovery key, which is the practical safety net if a passphrase is forgotten, though it has to be stored somewhere other than the vault folder.
Working with encrypted files day to day
The usual pattern is to install the desktop application, add a vault inside a folder that the cloud client already watches, and let the first full sync complete before doing anything else. Files are then worked on through the unlocked drive: documents, photos and project archives are written normally and re-encrypted on save. Because the cloud client only sees encrypted files, every save produces new ciphertext that has to be uploaded, and a change to a large file means that whole file is re-encrypted and transferred again. Mobile apps exist for reading the same vaults on a phone, and they are separate paid purchases rather than part of the free desktop program.
Configuration, formats and practical limits
On Windows the virtual drive depends on the WinFsp driver, which has to be present for a vault to mount as a drive letter. The vault format is documented, so an encrypted folder can be opened later with a different compatible client if the project ever stops shipping builds, and the passphrase is the only secret that matters. The limits are worth understanding before trusting the setup: the provider still sees how many files exist, roughly how large they are and when they change; anything already decrypted on screen can be read by other software on that machine; and a vault that is edited offline from two devices at once can produce sync conflicts that have to be resolved by hand. Keep the recovery key, if you create one, somewhere other than the cloud folder it protects.
When to choose something else
For whole-disk protection, use the encryption built into Windows or a container-based tool such as VeraCrypt, since Cryptomator only covers the vault folders. If you want end-to-end encrypted cloud storage without running anything locally, a provider with encryption built in is simpler. And if the goal is protecting credentials rather than documents, a password manager such as KeePassXC is the right category of tool.
- Best for
- People who want to keep using mainstream cloud storage while making sure the provider can only see encrypted files, without moving to a new service.
- Good to know
- Keep the passphrase and any recovery key outside the cloud folder. The provider can still see file sizes, counts and modification times, and editing a large file means that file is re-uploaded in full.
Cryptomator encrypts files before your cloud client ever sees them, then hands them back as a normal drive.
How to get started
- Install the Windows package and accept any driver prompt it shows, because Cryptomator needs the WinFsp driver on Windows.
- Create a vault inside a folder that your cloud client already synchronises, and choose a passphrase you will not lose.
- Unlock the vault and copy a few test files into the new drive letter.
- Wait for the cloud client to finish uploading the encrypted files before you add more.
- Lock the vault, confirm the folder now contains only unreadable files, then unlock it again to be sure your passphrase works.
Questions & answers
Can my cloud provider read the files?
No. Names, folders and contents are encrypted on your machine before upload. The provider can still see how many files there are, their approximate sizes and when they change.
What happens if I forget the passphrase?
The vault cannot be unlocked without it, unless you created a recovery key beforehand and kept it outside the cloud folder. Store that key somewhere separate.
Do I need a paid account?
The desktop application is free. Mobile apps are separate paid purchases, and the team product for shared vaults is a commercial add-on.