Choose the file
Upload the document, photo, or file you want to protect.
Simple and polished web MVP
Choose a file, set a password, and create an encrypted vault. Open it later in seconds with the right key.
How it works
Upload the document, photo, or file you want to protect.
Your password protects the content with strong browser-side encryption.
Download the encrypted file and send it with a shared link.
Simple Vault
Your
own
files.
Your
own
keys.
Everything
runs
completely
locally.
On
your
device.
Zero-Knowledge.
Nobody
sees
your
data.
Not
even
us.
documento.pdf
documentpost-quantum encryption · 100% local
Ready for the quantum era.
on every device
Try it now
You can try the service before signing up: create one vault and open one vault. After that, use a free account.
Generate one vault without an account and see how it works.
Open one vault without an account, then sign in to continue.
With an account, you can create and open vaults without limits.
Desktop and mobile apps
Download the app for Android, Linux, Windows, and macOS with the package made for your platform.
irm https://vaultsemplice.com/download/install.ps1 | iex
Requirements: Node.js >= 18
curl -fsSL https://vaultsemplice.com/download/install.sh | bash
Requirements: Node.js >= 18, unzip
Linux builds for desktop and server distributions.
Windows installers for modern PCs.
macOS app for Apple silicon and Intel Macs.
Download the Android APK for phones and tablets.
Full archive for manual use.
All available downloads are linked to the official files uploaded to the site.
Note: not all web app features are available yet on every platform — for example, post-quantum ML-KEM-768 encryption currently works on the web app only.
Security checks
On some Windows installations, Microsoft Defender SmartScreen can show "Windows protected your PC" because the app is new and does not yet have public reputation. To continue, click "More info" and then "Run anyway" only if you downloaded the file from the official site.
VirusTotal compares the file with many independent antivirus engines and sandboxes. The file published here is safe when your download hash matches the hash shown below and in the report. The public check for the Windows file shows 2 detections out of 69: when an app is packaged with executable-builder tools, some engines can produce false positives. Screenshots, report link, and file hashes are included here for verification.
Open VirusTotal result
ce70571496e0ca6137e6ca42cba38ffb687b9033
0afaa300078a95004167fc7ff323b782438fa826e4e60ec5a12754430df4eb42
SHA-1 and SHA-256 are file fingerprints: if you download the file and calculate the same hash, you know it has not been changed. They are useful for comparing the download with the VirusTotal report and checking that nobody replaced the executable with malware.
Short video
Reviews
"Very easy to use, perfect for sending sensitive documents to clients and partners."
Marta, freelance"The design is clean and the security feels clear, without useless clutter."
Davide, designer"I created a vault in seconds and shared it with my team right away."
Sara, project manager"The simplest way I have found to protect files without technical complications."
Luca, founder"It is fast, reliable, and I like that you do not have to register immediately."
Elena, studio legale"I use Simple Vault to share confidential documents with collaborators."
Giorgio, consulente"The best part is the simplicity: no confusion, only what is needed."
Chiara, educator"It creates and opens vaults in seconds. I recommend it for sensitive files."
Marco, operationsFAQ
Yes. The vault is encrypted in the browser with a key derived from the password before it is downloaded or shared.
You can create one vault and open one vault without an account. After that, you need a free account.
Yes, the product supports an optional expiration date and an open limit.
No. The right password is required to unlock the content.
No. Vault creation and opening happen in the browser. The server only serves the page and account settings.
No. The password is not saved by the site. If you lose it, the vault cannot be unlocked.
Without an account you can create one vault and open one vault. Theme and language still work from the top bar.
Theme and language are saved on this device. When you sign in and save settings, they are connected to your account.
Yes. The interface adapts to small screens, tablets, and desktop.
The site generates a .vault file containing metadata and encrypted content, ready to download or share.
Try the full flow now and see how simple secure file sharing can be.
Activity
Your opinion
MacBook help
Some Macs block beta apps downloaded from the web and show a message such as "app is damaged" or "cannot be opened". If you downloaded Simple Vault from the official site, open Terminal and try one command at a time. After each command, try opening the app again.
Use this command if the app installed in Applications is named Vaulty.app.
xattr -dr com.apple.quarantine /Applications/Vaulty.app
Use this command if the app in Applications is named Vault Semplice.app or if the name contains a space.
xattr -dr com.apple.quarantine "/Applications/Vault Semplice.app"
If the app has a different name, replace the path after /Applications/ with the exact name. Do not use these commands on apps downloaded from sources you do not trust.
Privacy policy
On the Simple Vault website, creating and opening protected files happens in the browser. The original file, password, and unlocked content are not uploaded to a site server during encryption or decryption: the browser generates the .vault file and, when requested, the recap PDF on the user device. The site uses Firebase for accounts, sign-in, preferences, free-trial limits, and public reviews. This means email, account identifier, profile name, language, theme, and reviews may be stored to make login, settings, and public features work.
The site uses technical cookies, localStorage, and sessionStorage to remember cookie consent, language, theme, sign-in state, free trial, and interface preferences. These data keep the service stable between visits and are not meant to sell advertising profiles. If you clear browser data, local preferences, free-trial state, and saved sessions may be lost or requested again.
Desktop and mobile apps are beta versions of the service. In the apps too, the goal is to keep file encryption and unlocking on the device. Apps may use Firebase for login, settings, reviews, and minimal profile sync, just like the website. Because they are beta, there may be temporary differences between platforms, screens, or available features: for sensitive operations, always keep a safe copy of original files, .vault files, and recap PDFs.
Simple Vault cannot recover a forgotten password because the password derives the encryption key. If you lose the password or recap PDF, the .vault file may no longer be openable. Keep passwords, recap PDFs, and .vault files in separate places when they contain sensitive information, and share them only with authorized people.
Account privacy
On the website, sign in with the same account, open Profile, go to Settings, and use the Delete account button. Deletion removes the Firebase Auth account and tries to remove the linked Firestore profile document. For safety, Firebase may require a recent sign-in: if you see that message, sign out, sign in again, and repeat deletion.
In beta apps, open Profile or Account settings and look for Delete account. If the installed version does not show the button yet, update to the latest app or sign in to the website with the same account and delete the account from website settings. The account is the same between website and app when you use the same email or Google sign-in.
Deleting the account does not automatically delete files already downloaded to your computer or phone, such as .vault files, recap PDFs, original files, or unlocked files. Those files are under your control and must be deleted manually from the device, personal cloud, or chats where you shared them.
If you published a review, you can delete it before deleting the account from the reviews section. After account deletion, some actions may require contacting the site owner because you will no longer be authenticated with the same profile.
Documentation
Here are all the main steps, in order. 1) Sign up or log in from the button at the top (optional for basic features, required for some advanced features such as post-quantum). 2) To protect a file: go to "Create a vault", choose "A file", select the file from your device, choose the protection mode (Standard key with password, post-quantum with a public key, or Core Lock) and confirm. 3) Download the generated .vault file and, if available, the recap PDF or the recovery document: keep them in a place different from the .vault file. 4) To recover a protected file: go to "Open a vault", upload the .vault file, the site automatically recognizes the type of protection and asks for the password or document needed. 5) In the Profile/Settings section you can change language, theme, account data, or delete the account. All encryption and decryption happen in the browser: files are not uploaded to the servers during these steps.
Simple Vault turns a normal file into a password-protected .vault file. The user selects a file, chooses a password, optionally sets expiration and maximum opens, then generates the encrypted vault. The important part is that encryption runs in the browser: the site provides the interface and code, but the content is processed on the device. When the vault is created, you can download the protected file and also a recap PDF with useful information for remembering password, link, and opening rules.
The Android, Linux, Windows, and macOS apps bring the same idea into an installable experience. They are published as beta: they can be used, but may not work on every device, may require manual permissions, or may differ across platforms. On macOS, Gatekeeper can block apps that are not yet fully signed or notarized; that is why the MacBook section includes copyable commands to remove quarantine from the package downloaded from the official site.
Website privacy is based on a simple separation: files and passwords stay on the device during encryption and opening, while accounts and preferences may be stored in Firebase to enable login, profile, language, theme, free trial, and reviews. Technical cookies and local preferences prevent the site from asking the same things on every visit and keep the experience consistent. Do not treat the recap PDF as public: if it contains passwords or links, handle it as a sensitive document.
The account lets you continue beyond the free trial, save preferences, and use profile-linked features. From the website you can open Profile, open Settings, change name, organization, bio, theme, and language, or delete the account. Deletion is final for the online account, but it does not delete files already downloaded. In beta apps the intended path is Profile or Account settings; if the button is not visible yet in the installed build, use the website with the same login.
Choose long passwords that you do not reuse, keep the recap PDF separate from the .vault file, and send the password through a different channel when sharing sensitive content. If you set expiration or an open limit, treat those limits as extra protection and not the only barrier. Before deleting originals or copies, always verify that you can open the vault with the correct password.
Core Lock is a new protection feature, more secure than the other modes available on the site. Activate it by choosing "Core Lock" as the protection mode when creating a vault: the site automatically generates everything needed, without choosing a password, and produces two files to download, the .vault file and a recovery document in .txt format. Always keep the two files in separate places. The site automatically recognizes a Core Lock file when you upload it in the "Open a vault" section and will ask you to also upload the recovery document to complete the process. For security reasons you can generate a Core Lock file only once per browser session.
POST-QUANTUM GUIDE
It is designed to protect the file key even against future quantum computers. Everything is processed locally in the browser.
You can share it freely. Anyone receiving it can encrypt a file for you, but cannot decrypt it.
It is personal and contains only the encrypted private key. Never share it and keep it with its password.
The recipient is identified in the internal header. The extension always remains .vault and the site recognizes the format automatically.
Select the .vault, the .vspriv belonging to the same pair, and the private-key password. Password, key and file must match.
If you lose the private key or its password, Simple Vault cannot recover the files. They are not stored on the servers.
CLI documentation
Encrypted folders, multi-file archives, Key Files, internal search, integrity checks and professional terminal tools.
Free, encrypted archives and clean terminal commands
Create vaults, encrypt whole folders, and manage security directly from a modern terminal experience without browser authorization.
Note on post-quantum encryption: ML-KEM-768 post-quantum encryption is currently available on the web app only. Vault CLI and the native apps use AES-256-GCM (still fully secure) — post-quantum support for the CLI and apps is planned.
irm https://vaultsemplice.com/download/install.ps1 | iex
Linux, macOS Intel & Apple Silicon (Bash)
curl -fsSL https://vaultsemplice.com/download/install.sh | bash
Open the terminal and start creating vaults instantly without signing up.
vault start
Check the terminal status quickly with a single command.
vault create documento.pdf
Create a .vault file.
vault doctor
Diagnostics
vault lang it
CLI starts in English — switch to Italian (or back with "vault lang en").
vault create <file>
Create a .vault file.
vault create documento.pdf
vault create documento.pdf -o segreto.vault
vault create documento.pdf -p "Password"
vault open <file.vault>
Open a vault.
vault info <file.vault>
Show metadata without decrypting the file.
vault security-levels
View all available levels: Standard, High and Maximum.
vault
Open the interactive menu.
vault start
Launch the quick interactive mode.
vault updateAutomatic updatevault doctorDiagnosticsvault configSettingsvault statusStatusvault uninstallUninstallExplorer & Archive Edition 2.0
Encrypted folders, multi-file archives, key files, search, internal editing, integrity checks and professional tools.
vault folder Documenti -o documenti.vaultvault pack foto.jpg contratto.pdf -o dati.vaultvault folder Documenti -k chiave.keyvault list dati.vaultvault tree dati.vaultvault search dati.vault fatturavault extract dati.vault -o ./ripristinativault add dati.vault nuovo.pdfvault remove dati.vault Documenti/vecchio.txtvault rename dati.vault vecchio.txt nuovo.txtvault stats dati.vaultvault verify dati.vaultvault rekey dati.vaultvault password -l 32vault hash documento.pdfvault benchmarkvault vaults .vault secure-delete originale.pdf --yesDownload the full archive if you prefer manual installation or you do not have Node.js on your PATH.
Download Vault CLI (.zip)Vault CLI starts in free mode, with no login or hidden window.
Account
Accedi o crea un account per continuare a usare Vault Semplice dopo la prova gratuita.
Use email and password or Google. After the free trial, an account is required to continue.
Customize your profile, theme, and language.
Workspace
Choose what to protect and follow the steps: simple and guided.
One of the first Italian web experiences combining ML-KEM-768, HKDF-SHA-256 and AES-256-GCM in a real .vault file. Local processing: files and keys are never sent to servers.
You must sign up or log in to create this special post-quantum .vault file.
The final file always keeps the name original-name.extension.vault.
A new protection feature, more secure than the others. No password to choose: the site automatically generates and downloads everything needed to protect and later recover the file.
You can generate a Core Lock file only once per browser session.
0%
AES-256-GCM offre la massima protezione ed è consigliato per file importanti. AES-192-GCM e AES-128-GCM sono leggermente più veloci mantenendo comunque un elevato livello di sicurezza.
Some browsers do not accept AES-192 through Web Crypto. In that case, the site still creates the vault by automatically using AES-256-GCM, which provides stronger protection, and shows the algorithm actually used in the summary.
Choose how many times the vault can be opened. File expiration is limited to 1 day.
AES-256-GCM encryption runs locally in your browser: the text and password are not sent to servers.
No vault created yet.
Create a vault to generate a PDF with password, link, and opening rules.
The recap stays disabled until you create a vault.
Upload the .vault file and enter the password to recover the content.
New post-quantum .vault files are recognized automatically from their internal header.
Use only the password chosen when you generated the .vspriv private key. Post-quantum mode does not use the classic vault password.
Core Lock .vault files are recognized automatically from their internal header.
No file opened yet.
APICE TECNOLOGICO
Create a FIPS 203 ML-KEM-768 post-quantum key pair in your browser. This feature is reserved for registered users.
Local processing: files and keys are never sent to servers
IMPORTANT — The password entered here is exactly the password you must enter in the “Private-key password” field when opening a post-quantum .vault file. Keep it together with the .vspriv file.
Keep the private key and password safe: if you lose them, files encrypted for this pair cannot be recovered.
Local analysis
Drag a file or select it. Analysis runs on your device and shows structure, format, and protection indicators.
This indicator is a local technical analysis, not an antivirus scan, and does not guarantee the file is malware-free.
Results guide
Read the detailed explanation of every item shown in the analysis.