Works offline

Your files. Your keys. Your control.

Encrypted file containers for confidential exchange, local storage, and sending through any channel you already use.

WindowsAndroidCLI WindowsCLI Linux

Works offline
23Cryptographic profiles
20Encryption layers Max
.lbxOne container format across platforms

Features

What LockBox does

Encrypted file containers without disk mounting

Free / Pro / Max

Multi-layer encryption

They only receive an encrypted file. Without the master password, all layer keys, and the correct order of layers, the contents and names remain inaccessible.

Create container
Max

Max container browser

Selective restore: extract a few files or folders from a large encrypted container while leaving the rest untouched.

Browse container
Max

Scheduled encrypted backups

Max can create LockBox containers on a schedule while the app stays open or minimized to the tray. It is useful for regular encrypted backups and safe transfer of confidential data.

LockBox for Android
Windows / Linux

CLI automation

Use --script when the procedure has several steps. Commands run in order, stop on the first error by default, and return a process exit code for the parent script.

Full CLI documentation
Max

Container destruction password

LockBox overwrites the container with encrypted random-looking data while preserving the original size.

How to enable

Security

Protection you can understand.

All processing is local on the computer. LockBox does not collect, upload, or send information about your files, folders, keys, passwords, license, device, or user account.

01 /

Container master password

The master password opens the encrypted metadata of the container. Metadata tells the program how many encryption layers exist and which algorithms were used.

AES-256-GCM · PBKDF2-SHA512
02 /

Encryption layers

If any layer key is wrong, that layer cannot be decrypted and unpacking stops with an error. The program cannot guess or recover missing keys.

AEAD / HMAC
03 /

Secret handling

For automation, prefer --master-env, --master-file, --layer-env, and --layer-file. Inline secrets work, but they may be saved in shell history or process logs.

CLI documentation

Know the limits

Protect your device and keep strong keys and tested backups. Creation, browsing and extraction use temporary plaintext files. Lost keys cannot be recovered. Destruction overwrites the selected container; other copies remain, and secure erasure on SSDs or flash storage is not guaranteed.

Downloads

Your security. On your device.

One container format across platforms

Before installing, compare your download’s SHA-256 hash with the published checksum.

SHA-256 checksums

Editions

Choose your level of control.

Pro and Max are perpetual licenses for 1 device.

Editions
LockBoxFree$0Pro$20Max$50
Encryption layers1320
AES / ChaCha20 / Serpent / Twofish / Camellia / ARIAAES-128
Compression
Split container
Crypto padding above container
Browse container
Scheduler
Container destruction password
Activation by requestGet LockBoxPro Max
What is a LockBox container?

A container is one encrypted file that stores the selected folder, nested folders, file contents, and encrypted file and folder names.

Is it safe to publish a container publicly?

The container can be transferred through public channels because the data inside remains encrypted. Do not publish passwords or keys together with the container.

Why do I need crypto padding?

Crypto padding adds encrypted random data to make the final container larger than the real payload. It helps hide the approximate size of the original files.

Why is the master password needed?

The master password opens the encrypted metadata of the container. Metadata tells the program how many encryption layers exist and which algorithms were used.

What happens if I enter a wrong layer key during unpacking?

If any layer key is wrong, that layer cannot be decrypted and unpacking stops with an error. The program cannot guess or recover missing keys.

What is the container destruction password?

It is a Max-only pressure-safety feature. A separate password silently overwrites the container instead of opening it, with no confirmation at the metadata password step.

Protect your device and keep strong keys and tested backups. Creation, browsing and extraction use temporary plaintext files. Lost keys cannot be recovered. Destruction overwrites the selected container; other copies remain, and secure erasure on SSDs or flash storage is not guaranteed.

Support and suggestions

For support requests, ideas, and product suggestions, write to support@logidev.io.

Contact support