NCryptAES

Complete User Manual

A cross-platform desktop app that locks your text, files and folders behind AES-256 encryption and a shared secret you choose. Drag, drop, type or paste — everything is encrypted on your own machine and never leaves it.

🖥️ macOS · Windows · Linux 🔐 AES-256-CBC + HMAC-SHA256 📄 Version 0.8.4 🗓️ Revised 14 September 2026

Overview

What NCryptAES Is

NCryptAES is a small, focused security tool for people who want strong encryption without a steep learning curve. Type a message or drop a file, choose a shared secret, and the app scrambles it into something only that same secret can unlock.

There are no accounts, no cloud, no keys to manage and nothing to configure. The encryption happens entirely on your computer using industry-standard algorithms, and the “key” is simply a passphrase that you and your recipient both know. Whether you are sending a private note through an ordinary email, or protecting a folder of documents before it goes onto a USB stick, the idea is the same: only someone with the secret can read it.

Encrypt Text

Turn any message into a safe block of characters you can paste into email, chat or notes.

Encrypt Files

Drag any file or whole folder onto the window and get a single encrypted .ncryptaes file back.

Stays on Your Device

All work happens locally. Nothing is uploaded, tracked or sent anywhere.

The one rule to remember. NCryptAES uses a symmetric secret — the same passphrase encrypts and decrypts. There is no “forgot password” and no back door. If the secret is lost, the data is gone for good. That is the point of real encryption, and it is why choosing and safely sharing your secret matters.

Where It Fits

Use Cases

NCryptAES is deliberately simple, which makes it useful in a surprising number of everyday situations. Here are the most common ways people put it to work.

Backing up & archiving

Encrypt documents and files before they go onto a USB stick, an external drive or a cloud backup. Even if the backup is lost or the cloud account is breached, the contents stay locked behind your secret.

Private information by email

Ordinary email is not private. Encrypt sensitive details — account numbers, credentials, personal notes — into a cipher block, paste it into the email, and share the secret separately so only your recipient can read it.

Posting on a public forum

Need to leave a message somewhere anyone can see — a forum, a comment thread, a shared document? Post the encrypted block instead. It looks like harmless gibberish to everyone except the person who holds the secret.

Encrypt & send files and folders

Drag a single Word document, a PDF, a photo or an entire folder onto the window and get one portable .ncryptaes file back. Send it however you like — the structure and original names are restored intact when your recipient decrypts it.

The common thread. In every case the encrypted output can travel over channels you don’t control — email, forums, cloud storage, a memory stick — because its safety never depends on the channel. It depends only on a secret you keep to yourself.

Getting Started

Installing & First Launch

System requirements

PlatformSupported versionsNotes
macOSRecent macOS releases (Intel & Apple Silicon)Full support, including spoken text.
Windows64-bit WindowsFull support, including spoken text.
LinuxModern 64-bit desktop distributionsFull support; the Speak feature is unavailable.

Running the app

  1. Open NCryptAES

    Launch the application the way you would any other — from the Applications folder, Start menu or your desktop. It opens as a single, compact window.

  2. You are ready immediately

    There is nothing to sign up for or set up. The status line at the bottom of the window reads “Ready …” when the app is waiting for you.

  3. Choose what you want to protect

    NCryptAES opens on the Text tab, ready for messages. Switch to the Files tab for files and folders. Both live in the same window.

Need two windows? You can open a second, independent copy of the working area at any time with Ctrl / Cmd + N (Actions ▸ New Instance) — handy for working with two different secrets side by side.

Free to Use

Licence & Activation

NCryptAES is free. Every feature works from the moment you launch it — there is no trial period that expires and nothing is locked away. A licence simply personalises your copy and removes the reminder to register.

When you first run the app, its title bar reads “NCryptAES: Trial License” and a small Free License link points to the website where you can request one. Encrypting and decrypting text, files and folders is fully available in this state — the licence changes nothing about how your data is protected.

Your data does not depend on the licence. Licensing only changes the title bar and hides the registration link. It never enables, disables or alters the encryption, so anything you encrypt on the trial opens exactly the same once you are licensed, and vice versa.

Getting your free licence

  1. Request it from the website

    Follow the Free License link in the window — or visit stevencholerton.com/ncryptaes-license — and ask for a licence. You will receive a small licence file named like NCryptAES_you@example.com.lic.

  2. Put the file next to the app

    Save the .lic file in the same folder as the NCryptAES application (on Windows, the folder that contains the program; on macOS, the folder that holds the app). You do not open or import it — the app finds it automatically.

  3. Restart NCryptAES

    Next time the app launches, the title bar changes to “NCryptAES: Licensed to: your name and the registration link disappears. That is all there is to it.

If a licence is rejected. Each licence is digitally signed and tied to NCryptAES. If the file is altered, incomplete, or was issued for a different product, the app shows a brief message and simply stays on the free trial — your work is unaffected. A licence issued for another application will name that application so you can see the mismatch.

Platform note. Licence activation runs on macOS and 64-bit Windows. On other builds the app stays on the trial title but every encryption and decryption feature works exactly the same.

Orientation

A Tour of the Window

NCryptAES keeps everything on one screen. The top half switches between two tabs; the bottom half holds the shared secret and a live status line. The annotated layout below shows every control on this tab.

NCryptAES Text Files Idle Time Clear Down: 284s Encrypt Decrypt Speak Encrypted text AQAMLAAr7Xk9… pQ2vHhZ0m8B… Plain text Meet me at 6pm… Shared Secret / Passphrase ••••••••••• Confirm the Shared Secret / Passphrase Encryption Complete … choltech 1 2 3 4 5 6 7
The single-window layout of NCryptAES, shown on the Text tab.
#ControlWhat it does
1Text / Files tabsSwitch between working with typed messages and working with files & folders. The app opens on Text.
2Encrypt / Decrypt / SpeakThe button column down the left edge. Run the operation, or read the plain text aloud (macOS & Windows). Each button has a tooltip describing what it does.
3Encrypted text areaThe centre box, shown as yellow on black. Where the scrambled cipher text appears, and where you paste cipher text to decrypt.
4Plain text areaThe right-hand box. Where you type or paste a readable message, and where decrypted text appears.
5Shared secret & confirmYour passphrase. The confirm field guards against a typo when encrypting. Characters are masked.
6Status lineLive feedback — “Ready …”, “Encryption Complete …”, “Decryption Complete …”, progress during file drops, and “Secret and Text Cleared After Inactivity …” once the idle timer fires.
7Idle clear-down countdownAppears at the top right only while the secret or either text box holds something, counting down the five minutes until all three are wiped. Any typing restarts it, and it disappears once the fields are empty.

Switching to the Files tab swaps that whole upper area for a single drop list. Everything below it — the shared secret, the status line — and the countdown above it are shared by both tabs and stay exactly where they are.

NCryptAES Text Files Idle Time Clear Down: 284s Drop files or folders here 2026/09/08 20:41:07 ~ Report.pdf > Report.pdf.ncryptaes 2026/09/08 20:41:12 ~ Accounts > Accounts.ncryptaes 2026/09/08 20:42:03 ~ Notes.ncryptaes > Notes Shared Secret / Passphrase ••••••••••• Confirm the Shared Secret / Passphrase 3 of 3 Dropped Item(s) Written to the Desktop … choltech 8
The same window on the Files tab — one drop list in place of the buttons and text areas.
#ControlWhat it does
8File activity listThe drop target for files and folders, and the log of what happened. Each completed item adds a timestamped row in the form date ~ original > result. Dropping a mix of ordinary files and .ncryptaes files is fine — each is routed on its own extension in a single pass.

The window remembers its size and position between sessions, and can be resized freely (minimum 600 × 418).

The Key to Everything

Choosing Your Shared Secret

Your shared secret (also called a passphrase) is the only thing that can unlock what you encrypt. NCryptAES enforces a sensible length and, when encrypting, asks you to confirm it.

12
MINIMUM CHARACTERS
64
MAXIMUM CHARACTERS
ENTERED TO CONFIRM
•••
ALWAYS MASKED ON SCREEN

The rules NCryptAES enforces

  • The secret must be between 12 and 64 characters long. Anything shorter or longer is rejected with a prompt.
  • When encrypting, you must type the secret into both fields and they must match exactly — this stops a single mistyped character from producing something you can never open again.
  • When decrypting, only the first field is needed.
  • The secret is never shown in clear text and is never saved to disk. It is wiped from memory the moment an operation finishes.

There is no recovery. If you forget the secret, the encrypted text or file cannot be opened by anyone — including the app’s author. Keep the secret somewhere safe and separate from the encrypted data itself.

How to pick a strong one

✅ Do

  • Use a memorable passphrase of several unrelated words, e.g. violet-anchor-ceramic-tuesday.
  • Aim comfortably above the 12-character minimum.
  • Share it through a different channel than the encrypted data (say the words on a phone call, not in the same email).

🚫 Avoid

  • Names, birthdays, or a single dictionary word.
  • Re-using a password you use elsewhere.
  • Sending the secret in the same message as the cipher text — that defeats the purpose.

Everyday Use

Encrypting & Decrypting Text

The Text tab is the fastest way to protect a short message. The result is a block of ordinary characters (Base64) that is safe to paste into an email, a chat message or a note.

To encrypt a message

  1. Type or paste your message

    Put the readable text into the plain text box on the right.

  2. Enter your secret twice

    Type your chosen passphrase into the secret field and again into the confirm field below it.

  3. Press Encrypt

    The scrambled cipher text appears in the centre box in yellow on black, and the status line reads “Encryption Complete …”. Your secret is cleared automatically.

  4. Copy and send

    Use Edit ▸ Copy Cipher Text to Clipboard, then paste the block wherever you like. Share the secret separately.

To decrypt a message

  1. Paste the cipher text

    Put the scrambled block into the encrypted text box in the centre.

  2. Enter the secret

    Type the shared secret into the first field (no confirmation needed to decrypt).

  3. Press Decrypt

    The original message appears in the plain text box on the right and the status line reads “Decryption Complete …”. If the secret is wrong — or the text was altered in transit — decryption fails safely and nothing is shown.

Speak. On macOS and Windows, the Speak button reads the plain text box aloud — useful for reading a decrypted message without it lingering on screen, or for accessibility.

Copying plain text. Edit ▸ Copy Clear Text to Clipboard warns you first, then automatically wipes the clipboard 30 seconds later so a decrypted secret does not sit there indefinitely.

Files & Folders

Encrypting by Drag & Drop

The Files tab turns any file — or an entire folder with its whole structure — into a single, portable encrypted file. Everything is driven by drag and drop.

📁 Report/ NCryptAES · Files drop here Inside the app ① Zip (name + tree) ② Encrypt bytes ③ Wipe the temp zip 🔒 Report.ncryptaes → Desktop
Encrypting: the item is zipped, the zip’s bytes are encrypted, the temporary zip is securely wiped, and a single .ncryptaes file lands on your Desktop.

To encrypt files or folders

  1. Open the Files tab & enter your secret

    Type the shared secret into both fields (encrypting always needs the confirmation).

  2. Drag items onto the list

    Drop one or many files and/or folders onto the large activity list. A folder keeps its entire internal structure.

  3. Collect the result from the Desktop

    Each item becomes <OriginalName>.ncryptaes on your Desktop. The activity list logs each one with a timestamp. If a name is taken, -1, -2… is added so nothing is ever overwritten.

To decrypt a .ncryptaes file

Enter the secret and drop the .ncryptaes file onto the same list. The original file or folder is restored to your Desktop under its original name. A wrong secret or a tampered file fails safely with a warning, and nothing is written.

Mixed drops are fine. You can drop encrypted and un-encrypted items in the same go — NCryptAES looks at each item’s extension and encrypts or decrypts it accordingly, all in one pass. The status line shows a running total such as “3 of 4 Dropped Item(s) Written to the Desktop …”.

Size limit: 1 GB. Because strong CBC encryption has no streaming mode, each item is held in memory while it is processed. Anything larger than 1 GB once compressed is politely refused. For very large data, encrypt a compressed archive or split it first.

Under the Hood

How the Security Works

You do not need to understand any of this to use NCryptAES — but if you are the kind of person who likes to know exactly what is protecting your data, here it is. The design follows the modern Encrypt-then-MAC pattern with well-vetted, standard building blocks.

AES-256

The cipher that scrambles your data, in CBC mode with PKCS7 padding.

PBKDF2

Stretches your passphrase into keys with 800,000 SHA-256 rounds.

HMAC-SHA256

A tamper seal checked before anything is decrypted.

Random salt & IV

Fresh 16-byte random values every time, so output never repeats.

From passphrase to keys

Your passphrase is never used directly as an encryption key. Instead, PBKDF2 combines it with a random salt and runs it through 800,000 rounds of hashing to derive 64 bytes, which are split into two independent 32-byte keys — one to encrypt, a separate one to authenticate. This “key separation” is a deliberate best practice.

Passphrase + random salt PBKDF2 · SHA-256 800,000 rounds → 64 bytes 32-byte AES key encrypts your data 32-byte HMAC key seals & verifies it
One passphrase becomes two separate keys — the encryption key never doubles as the authentication key.

How much work is 800,000 rounds?

The number of PBKDF2 rounds is a deliberate speed bump: it makes each guess of the passphrase expensive for an attacker, without you noticing the fraction of a second it adds. NCryptAES sets the bar above the current OWASP recommendation.

NCryptAES 800,000 OWASP minimum 600,000 Older guidance (2015) 10,000 0 500,000 1,000,000 PBKDF2-HMAC-SHA256 iterations per unlock attempt
NCryptAES uses 800,000 iterations — a third above the OWASP minimum, and 80× older guidance. The count is stored in each file, so it can be raised in future without breaking older files.

Encrypt, then seal, then verify

After encryption, NCryptAES computes an HMAC “seal” over the whole package and appends it. On the way back, that seal is checked in constant time before a single byte is decrypted. If anything was changed — even one bit — or the secret is wrong, the app stops right there and reports a failure. This ordering closes an entire class of classic attacks.

What this means for you. A file that has been corrupted, truncated, or deliberately tampered with will never silently produce wrong output. You either get your exact original data back, or a clear failure — never something in between.

Reference

Anatomy of an Encrypted File

Every encrypted output — whether the Base64 text block or a .ncryptaes file — has the same underlying structure. Understanding it is optional, but it shows there is no hidden magic: just a small header, your encrypted data, and the tamper seal.

1 4 16 16 variable 32 Ver. Iter. Salt IV Ciphertext HMAC the HMAC seals everything to its left byte 0 end
The package layout. A .ncryptaes file stores these bytes raw; the Text tab wraps the very same bytes in Base64.
Version Iteration count Salt Initialisation vector Ciphertext Tamper seal
FieldSizePurpose
Version1 byteIdentifies the format so future versions can decrypt older files safely.
Iteration count4 bytesHow many PBKDF2 rounds were used — stored so the count can be increased later without breaking existing files.
Salt16 bytesRandom per-file value that makes the derived keys unique even for the same passphrase.
IV16 bytesRandom initialisation vector so identical inputs never produce identical output.
CiphertextvariableYour data, encrypted with AES-256-CBC.
HMAC seal32 bytesAuthentication tag over the entire header and ciphertext, verified before any decryption.

Peace of Mind

Built-in Safety Features

Beyond the core encryption, NCryptAES takes several quiet precautions to keep sensitive material from lingering where it shouldn’t.

Idle auto-clear

If you walk away, a 5-minute countdown (shown top-right) wipes the secret, plain text and cipher text automatically. Any typing resets the timer.

Secret wiped after every use

The passphrase fields are emptied the instant an encrypt or decrypt finishes — success or failure — and the secret is scrubbed from memory.

Temporary files shredded

While processing files, the app stages work in a private, randomly-named folder and overwrites the temporary plaintext before deleting it.

Safe restore

Decrypted archives are screened for booby-trapped paths before extraction, and existing Desktop files are never overwritten — a numbered suffix is added instead.

Clipboard timeout

Plain text copied to the clipboard is automatically cleared after 30 seconds so it can’t be pasted by accident later.

Nothing leaves your machine

No network calls, no telemetry, no accounts. Only window size and position are remembered between sessions.

Help

Troubleshooting & FAQ
SituationWhat’s happening & what to do
The shared secret
“Please Input a Shared Secret of 12-64 Characters …”Your passphrase is too short or too long. Choose one between 12 and 64 characters.
“Please Confirm the Shared Secret …”The confirmation field is empty. Encrypting always needs the secret typed into both fields; decrypting needs only the first.
“Shared Secret and Confirmation Must Match …”The two secret fields differ. Re-type the passphrase carefully in both when encrypting.
The Text tab
“Decryption Failed: Wrong Secret or Corrupted / Tampered Data …”Either the secret is wrong, or the cipher text was altered. Check the passphrase and that the full, unmodified block was pasted — a truncated block always fails.
“Encryption Failed …”The text could not be encrypted. Check that the plain text box actually holds content, then try again.
Nothing happens when I press a buttonAn empty text box just beeps. Make sure the relevant box has content and the secret is entered.
The Files tab
“… Could Not be Decrypted: Wrong Secret or Corrupted / Tampered Data …”The file-drop version of the message above: the secret is wrong, or the .ncryptaes file was altered or truncated in transit. Nothing is written to the Desktop when this happens.
“… is Already Encrypted …”You dropped a .ncryptaes file while it was being treated as something to encrypt. Encrypted files are left alone rather than encrypted twice.
“… is a Folder and Cannot be Decrypted …”A folder named .ncryptaes was dropped. NCryptAES only ever produces single files, so this did not come from the app.
“… is Too Large to Encrypt: The Limit is 1 GB Once Compressed …”The limit applies to the item after compression, so a large but highly compressible folder may still be fine. If it genuinely exceeds 1 GB zipped, split it and encrypt the parts separately.
“… is Too Large to Decrypt: The Limit is 1 GB …”The same cap on the way back. Any file NCryptAES produced itself is within it, so this normally means the file did not come from this app.
“… Contains an Unsafe Path and Was Not Restored …”A decrypted archive contained a suspicious file path and was refused for your safety. Only decrypt files from people you trust.
“… Did Not Contain Anything to Restore …”The file decrypted correctly but the archive inside held nothing to write out.
“… Could Not be Read / Created / Compressed …” and similarSomething went wrong at the file-system level rather than in the encryption — a missing permission, a full disk, or an item that moved or was deleted mid-operation. Nothing partial is left behind: check the item is still where you dropped it from and that the Desktop is writable, then try again.
General
“Speech is Not Supported on this Platform …”The Speak feature is available on macOS and Windows only, not Linux.
Everything cleared while I was awayThe 5-minute idle timer wiped the fields for safety and the status line reads “Secret and Text Cleared After Inactivity …”. This is expected — simply start again.
I lost my passphraseUnfortunately the data cannot be recovered. There is no back door by design.

Do It Right

Best-Practice Checklist

🔑 Handling secrets

  • Use a long, memorable multi-word passphrase.
  • Share it over a different channel to the data.
  • Never store the secret next to the encrypted file.
  • Use a fresh secret per recipient or per project where practical.

📦 Handling data

  • Keep the entire cipher text block — clipping it makes it undecryptable.
  • Verify you can decrypt a file before deleting the original.
  • Combine with full-disk encryption for the strongest protection of temporary data.
  • Only decrypt .ncryptaes files from people you trust.

In one sentence

Type or drop what you want to protect, choose a strong secret you keep safe and share carefully, and NCryptAES does the rest — locally, verifiably, and with no way in for anyone who doesn’t hold the secret.