Zum Hauptinhalt springen
Better Password Generator

Cloud services like Dropbox, Google Drive, OneDrive, and iCloud store your data on servers that the provider has access to. Without additional encryption, this data can theoretically be viewed by employees, authorities, or in the event of a data breach.

The solution: encrypt files before uploading — then the provider is just an oblivious storage container.

Server-Side vs. Client-Side Encryption

EncryptionBy whomWho can decrypt
Server-side (Standard)Cloud providerProvider + You
End-to-EndPartially by providerOnly you (sometimes)
Client-side (Cryptomator)By you, locallyOnly you

Client-side encryption is the most secure option: only you hold the key.

Cryptomator – The Easiest Solution for All Cloud Services

Cryptomator is a free, open-source tool that creates an encrypted vault inside your cloud folder. Files are automatically encrypted when saved and decrypted when opened.

How it works:

  1. Cryptomator creates a vault folder (e.g., inside Dropbox)
  2. This folder contains only encrypted data (unreadable to Dropbox)
  3. Cryptomator opens the vault as a virtual drive
  4. You work with your files normally — encryption happens in the background

Setup:

  1. cryptomator.org → download for free on Windows/Mac/Linux
  2. "Create New Vault" → save inside your cloud folder
  3. Set a vault password → use the Password Generator: at least 20 characters
  4. Open the vault → mounted as a drive → store files normally

Compatible with: Dropbox, Google Drive, OneDrive, iCloud, Nextcloud, any cloud-synced folder

Boxcryptor – Alternative for Teams

Boxcryptor (now integrated into Dropbox) was a commercial alternative to Cryptomator, especially for teams and enterprise environments. For private users: Cryptomator is the better (and free) choice.

Which Cloud Services Offer Built-in Encryption?

ServiceBuilt-in E2E Encryption
DropboxNo (server-side encrypted)
Google DriveNo (server-side encrypted)
OneDriveNo (except Personal Vault)
iCloudPartially (opt-in Advanced Data Protection)
Proton DriveYes (end-to-end)
TresoritYes (end-to-end, paid)

Recommendation: Proton Drive for privacy-conscious users with a free E2E option.

Password for Your Encrypted Vault

The password for your Cryptomator vault is the only protection for your encrypted data. Choose a very strong password:

Warning: If the vault password is forgotten, the data is permanently lost. Cryptomator has no master access.

Frequently Asked Questions