100% client-side · no upload · no account

Secure your files.
Nothing leaves this device.

27 tools to encrypt, redact, anonymize, and dispose of files — every operation runs inside your browser. No upload. No account. No server ever sees your data.

One deliberate exception: FileX Send stores your file — always encrypted, never readable by us — only until it's downloaded or expires.

Four things you won't find in a normal file tool.

Most "private" file tools upload your file and promise to behave. These four are why FileX doesn't have to make that promise.

The .filex container

AES-256-GCM with an FLX1 magic header and a deterministic, documented wire format. An open specification you can read — not a black box you have to trust.

See the format →

FileX ID — quantum-safe sharing

Hybrid X25519 + ML-KEM-768 keys. Encrypt a file to someone's public ID without ever agreeing on a password, and stay safe even if one algorithm later falls.

Create an ID →

Signed evidence — ML-DSA-65

Erasure certificates and audit reports carry a post-quantum signature and an integrity hash. Anyone can verify one — years later, without a key or an account from us.

Verify a report →

Nothing leaves your device

Every tool below runs entirely in your browser via the Web Crypto API. No telemetry, no tracking pixels, and no third-party scripts on any tool page.

Read the privacy policy →

Use any tool right now — free, no sign-up.

Pick a tool and drop a file in. Nothing uploads; the live counter at the bottom of this page stays at zero while you work.

Simple, honest pricing

Free forever. Paid when you need the deep tools.

Every core security tool is free with no account. Paid plans unlock the PDF editor, image redaction, pseudonymization, uncapped erasure, and bigger FileX Send limits.

Compare all 27 tools across plans → · Already have a license key?

The one exception

One tool that touches our servers — on purpose.

Every other tool on this page runs entirely in your browser. FileX Send can't: a link you share has to work later, on someone else's device, so the file has to rest somewhere in between. We say so plainly rather than burying it.

What makes it different from a normal transfer service is what we hold. Your file is encrypted in your browser before a single byte leaves your device, and the key lives only in the link's # fragment — which browsers never send to any server. We store ciphertext we cannot read, and delete it the moment it's collected or expires.

Encrypted firstClient-side, before upload
Filename hiddenNever sent to our server
Auto-expiryEvery link has a deadline
Auto-deleteRemoved after download
Free 10 MB · 24-hour link · 3 sends/day
Pro & Lifetime 250 MB · 7-day link
Team 2 GB · 30-day link · password-protected

All 27 tools, grouped by what you're about to do.

The same grouping the tool nav above uses — so a tool lives in the same place however you find it.

Built by someone who audits this for a living.

ISO 27001 Lead Auditor 12+ years in information security, building the tooling he wanted to use.
Engine components open-source The erasure-certificate format is byte-identical to the public FileX Eraser CLI, and verifiable by either.
No telemetry, ever No tracking pixels and no third-party scripts on tool pages — a strict CSP blocks them outright.

Frequently asked questions

Do my files really never leave my device?

Yes, for every tool except FileX Send. Encryption, redaction, metadata scrubbing, and PDF editing all run in your browser via the Web Crypto API and self-hosted libraries — nothing is uploaded. FileX Send is the one deliberate exception: see the next question.

What's the exception with FileX Send?

FileX Send encrypts your file in your browser before anything leaves your device, then stores only that ciphertext — never the plaintext or the decryption key — until the recipient downloads it or the link expires. Read the full threat model for exactly what we can and cannot see.

Is the .filex file format open?

Yes. The .filex container (FLX1 magic header) uses AES-256-GCM with a documented, deterministic wire format. You can inspect or decrypt a .filex file with FileX itself, entirely offline.

What algorithms does FileX use?

AES-256-GCM for encryption, Argon2id for password-derived keys, a hybrid of X25519 and ML-KEM-768 for FileX ID key exchange, and ML-DSA-65 for signatures on erasure certificates and audit reports — all standard, audited primitives, no hand-rolled crypto.

How do I verify a signed report from FileX?

Drop the certificate or report file into the Verify tool. FileX recomputes its SHA-256 integrity hash and, if it was signed, checks the ML-DSA-65 signature against the signer’s FileX ID — entirely in your browser, no upload.

How is FileX different from Smallpdf or iLoveIMG?

Those tools upload your file to a server to process it. Every FileX tool except Send runs the same kind of operation locally in your browser instead, and the deeper tools (FileX ID, signed audit reports, erasure certificates) go beyond basic PDF utilities into compliance-ready, independently verifiable output.

Ready when you are — every free tool works without an account.

RUNNING LOCALLY
your files uploaded 0 B
sent to a server 0 files
processed locally 0
file contents have not touched the internet
FILEX SEND — different from every other tool here
This file is encrypted in your browser, then stored (still encrypted) on our server until it's downloaded or the link expires.