Cryptomator: keep your cloud, encrypt your documents
Understand the vault, the unlocked drive and recovery before entrusting important files to them.
Before you get started
What to expect
Cryptomator encrypts files before they are stored in a folder, for example one synchronised to a cloud service. You work through an unlocked view while the provider receives encrypted data. This protects stored content but replaces neither backups nor computer security.
The folder you would rather keep private
You already use cloud storage and want to keep documents there without sending their readable contents to the provider. Cryptomator creates a vault in a folder you choose, so you can encrypt those files while keeping your sync service.
The compromise is tangible: browsing those files directly in the cloud’s web interface becomes less convenient. You need a compatible client to open the vault. Choose documents that justify this extra step before moving your entire folder tree.
One vault, two views to keep distinct
The vault folder contains encrypted data. Unlocking it presents a virtual drive where the files are usable. Encryption and decryption happen during access; synchronising to the cloud remains the storage tool’s job.
Do not manually rename technical files inside the encrypted folder. Work on documents through the unlocked view. When copying or backing up the vault, follow the application’s instructions and include its complete structure.
| Location | What you do there |
|---|---|
| Synchronised encrypted folder | Leave it to the sync client and backup system |
| Unlocked drive | Open, organise and edit your documents |
| Downloads, desktop and attachments | Watch for readable copies outside the vault |
Learn with files that do not matter
A useful first vault contains a fictional text, an ordinary image and a document you can recreate. Follow the full journey: creation, locking, synchronisation, opening on another device and recovery from a copy.
- Install Cryptomator from its official source and check the client’s terms for each platform you intend to use.
- Create a test vault in the appropriate folder for your storage setup. Choose a unique password and arrange how to retain it.
- Unlock it, copy in your sample files, then close applications using them before locking the vault.
- Wait for synchronisation to finish. On a second compatible device, open the received copy and check its contents before editing anything.
- Prepare a vault backup and recovery method. Practise opening a separate copy without replacing the live vault.
What remains visible and vulnerable
Cryptomator protects content and filenames, among other things. Its security model does not hide every piece of metadata: sizes, dates and file counts can still reveal clues. A compromised computer can also read what you access while the vault is open.
Consider the application handling a document. An editor may create a temporary or working copy outside the vault. Disk encryption and session locking therefore still matter for the device. Cryptomator addresses a storage location, not the entire life of a document.
Keep the recovery key separately
The recovery key lets you set a new vault password. That makes it a powerful access secret. Without either the password or this key, the developer has no magic button to open your data.
Storage must solve two problems: prevent unwanted access and remain reachable if the computer disappears. Protected paper or independent encrypted storage may suit your circumstances. Do not keep the only recovery route inside the vault it needs to unlock.
Handle sync conflicts
Concurrent edits can create conflicting copies. Cryptomator exposes them in the decrypted view, but deciding which content to keep is your job. It does not turn an ordinary document into a collaborative editor.
Wait for synchronisation before opening a file on another device and before handing over work. If a conflict appears, preserve both versions while comparing them. Backup history exists precisely to help you recover from a wrong decision.
Old copies after a password change
A password change does not re-encrypt every file with new data keys. An older key-file version retained in history may therefore remain usable with the old secret. If that secret was exposed, examine the official procedure for creating a new vault and migrating the data.
This is a reason to choose the first password carefully and treat histories and backups as copies in their own right. Verify the new copy before a security migration; do not destroy your only recovery route in a hurry.
For a personal folder, prepare recovery and check synchronisation between your devices. If several people edit the same files, examine potential conflicts and collaboration needs before moving the folder into a vault.
From the provider
Cryptomator
Downloads, compatibility and current terms.
Frequently asked questions
Practical questions
Are files still protected while the vault is open?
The stored copy remains encrypted, but authorised applications and processes on the computer can access the unlocked view. Cryptomator therefore does not replace operating-system security. Lock the vault when you finish.
Read more: What remains visible and vulnerable #Link to this answerDoes changing the password protect an old stolen vault copy?
Not retroactively. An old copy may remain usable with the old secret. A password change does not remove data someone already copied. Assess what was exposed before deciding what to do next.
Read more: Old copies after a password change #Link to this answerCheck and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
- Cryptomator: encryption architecture ↗docs.cryptomator.org ·
- Cryptomator: security model and limitations ↗docs.cryptomator.org ·
- Cryptomator: passwords and recovery keys ↗docs.cryptomator.org ·
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.