AES-256-GCM · Argon2id or ML-KEM-768 + X25519 · optional GPG · Self-contained


GPG Layer Detected

A fresh ML-KEM-768 + X25519 keypair is generated and the content is encrypted to its public key. You'll receive a Recovery Key (the private key) below — store it somewhere safe and separate from this file. Anyone holding the encrypted secret cannot read it without that Recovery Key, and the hybrid stays secure even against a future quantum computer.

Add GPG LayerEncrypt with GPG before the outer layer (two-layer encryption)
GPG Configuration