This article first appeared in 2023. Three years is a long time in tooling: one product on the original list has been shut down entirely, another has been declared dormant by its own author, and the rest have shipped meaningful changes. This is a full review rather than a touch-up.
Encryption is the one privacy control that keeps working after everything else has failed. Access control assumes the identity system is intact. Network segmentation assumes the perimeter holds. Encryption assumes nothing: if the ciphertext leaks and the key does not, the data is still unintelligible. That is why regulators name it explicitly, and why it belongs in every privacy engineering toolkit rather than only in the security architecture diagram.
What changed since the 2023 edition
Boxcryptor has ceased operations entirely and EncFS has been declared dormant by its author. Both have been removed and replaced with gocryptfs and age. Native full-disk encryption has been added, because it is the control most organisations already own and forget to count. Every remaining tool has been re-checked against its current release.
At a glance
| Tool | Best for | Maintained | Cost |
|---|---|---|---|
| BitLocker / FileVault / LUKS2 | Whole-device protection | Included with the OS | |
| VeraCrypt | Portable encrypted volumes | Free | |
| Cryptomator | Client-side cloud encryption | Free desktop, paid mobile and Hub | |
| gocryptfs | Encrypted directories on servers | Free | |
| age | Scripts, pipelines and backups | Free | |
| GnuPG | Third-party exchange and signing | Free | |
| 7-Zip | Ad-hoc encrypted archives | Free | |
| AxCrypt / Xecrets Ez | Non-technical desktop users | Freemium |
Which one does this situation call for?
| If the requirement is to… | Reach for |
|---|---|
| Protect a whole laptop or workstation | Native full-disk encryption |
| Carry an encrypted volume on a USB stick or external drive | VeraCrypt |
| Use Dropbox, OneDrive or Google Drive without trusting the provider | Cryptomator |
| Encrypt a directory on a Linux server or development machine | gocryptfs |
| Encrypt files inside scripts, pipelines and backups | age |
| Exchange files or email with a third party who already has a key | GnuPG |
| Send an encrypted archive to someone with no special software | 7-Zip |
| Give non-technical colleagues a right-click encryption tool | AxCrypt or Xecrets Ez |
These are not alternatives to each other. A realistic setup uses three or four of them at different layers.
1. Native full-disk encryption: BitLocker, FileVault, LUKS2
Status — August 2026
Actively maintained by Microsoft, Apple and the Linux community respectively.
The tool most organisations forget to count is the one already built into the operating system. BitLocker on Windows, FileVault on macOS and LUKS2 with dm-crypt on Linux all provide transparent full-volume encryption with hardware-backed key storage: a TPM, a Secure Enclave, or a passphrase-derived key using Argon2id in the case of LUKS2.
It is the baseline control an auditor expects to see, it costs nothing, and it protects the single most common data loss scenario in practice: a device that is lost, stolen, sold or sent for repair.
Where it fits
- Private use
- Every laptop and every external drive. Turn it on at setup rather than retrofitting it.
- Business use
- A fleet-wide policy with centrally escrowed recovery keys, applied and verified through device management rather than left to individual users.
Where the real work is
Turning encryption on is trivial. Managing recovery keys is not. BitLocker recovery keys belong in Entra ID, FileVault institutional keys in an MDM, and LUKS headers in a controlled backup location. Recovery key management is what turns a working control into an evidenced one during certification.
What it gives you
- No licensing cost and no additional software to deploy or patch
- Transparent to users, so adoption is not a behavioural problem
- Hardware-backed key protection resists offline attacks on the drive
- Universally recognised by auditors and customer security questionnaires
What it does not
- Protect a running, unlocked machine, which is where most real compromises happen
- Keep the vendor out, since cloud key escrow gives the provider or tenant administrator a path to the data
- Offer the full feature set on Windows Home, where behaviour around firmware updates and suspension trips people up
- Cover data in transit, data in memory, or the backup nobody encrypted
2. VeraCrypt
Status — August 2026
Actively maintained. Version 1.26.29 was released on 9 June 2026, adding Argon2id as an alternative memory-hard KDF for non-system volumes.
VeraCrypt is the successor to TrueCrypt, which was abandoned in 2014. It creates encrypted containers that mount as ordinary drives, and it can encrypt entire partitions or system drives with pre-boot authentication.
The project’s centre of gravity has shifted: lead developer Mounir Idrassi now operates primarily through AM Crypto in Japan, with IDRIX in France continuing in a reduced capacity, and the primary website has moved accordingly.
Hidden volumes created before 1.26.29 need recreating
Version 1.26.29 fixed a flaw affecting hidden volumes created inside file containers with versions 1.26.6 through 1.26.28. The flaw undermines plausible deniability specifically, which is the entire point of the feature. Anyone relying on hidden volumes should recreate them with the current release rather than assume an upgrade is sufficient.
Nothing else gives a portable, cross-platform, self-contained encrypted volume that is indistinguishable from random data when dismounted. That property is what makes it useful for anything that physically travels.
Where it fits
- Private use
- USB drives, external backup disks, and any single archive of sensitive personal records that should be mounted only when in use.
- Business use
- Field devices and physical media transfers where the recipient’s infrastructure cannot be relied on. It is a defensible answer when a client asks how a data extract was protected in transit on physical media, and a poor fit for anything that synchronises to cloud storage.
What it gives you
- Genuine full-disk and system-partition encryption, including pre-boot authentication
- Argon2id key derivation, in line with modern standards against GPU and ASIC brute-forcing
- Independent audits, with a long history of addressing findings publicly
- Cross-platform and free, multi-licensed under Apache 2.0 and the TrueCrypt licence
What it does not
- Spread the maintenance burden, since the project depends heavily on a single developer
- Sync efficiently to cloud storage, because a container is one monolithic file
- Match native performance on NVMe drives, so benchmark before high-IOPS use
- Deploy smoothly everywhere this year, after a temporary suspension of the developer’s code-signing certificates
- Open TrueCrypt volumes since 1.26.7, so legacy volumes need an older build to migrate
3. Cryptomator
Status — August 2026
Actively maintained by Skymatic, which marked ten years of the project in March 2026. Desktop version 1.19.x is current.
Cryptomator encrypts individual files client-side before they reach cloud storage, exposing them through a virtual drive. Because each file is encrypted separately, cloud synchronisation stays efficient, which is the opposite of the VeraCrypt container problem.
It solves the specific problem of using Dropbox, OneDrive, Google Drive or any WebDAV or S3 target without extending trust to the provider. File contents and file names are both encrypted.
Where it fits
- Private use
- Any personal cloud storage holding financial documents, identity documents, health records or family archives.
- Business use
- Small teams that need zero-knowledge storage on top of a cloud suite they are contractually stuck with. Cryptomator Hub adds identity-integrated key management, user and group management, and emergency access, which is what answers the question of what happens when the key holder leaves.
Patch Hub deployments promptly
Several CVEs were fixed in 2026 in Hub-related code paths, including a possible man-in-the-middle attack via tampered vault configuration. Self-hosted Hub instances are only as safe as the patching cadence behind them.
What it gives you
- Per-file encryption, so cloud synchronisation stays efficient and incremental
- GPLv3 licensing, so an acquisition cannot take the technology off the market
- Windows, macOS, Linux, iOS and Android support with a genuinely usable interface
- Real team key management through Hub, rather than shared passwords
What it does not
- Come free on every platform, since mobile apps and Hub are paid and pricing changed in 2026
- Hide metadata, because file sizes and object counts per directory remain visible
- Stay safe without patching, as the 2026 Hub advisories demonstrate
- Run as lightly as a native client, being Java-based on the desktop
4. gocryptfs
Status — August 2026
Actively maintained, and the migration target recommended by the author of EncFS.
gocryptfs is an encrypted overlay filesystem for Linux and macOS. It is pointed at a directory of ciphertext and mounts a plaintext view through FUSE. It was built explicitly to fix the design weaknesses of EncFS, and it uses authenticated encryption so that tampering with ciphertext is detected rather than silently decrypted into garbage.
Creating and mounting an encrypted directory
gocryptfs -init /srv/data-cipher
gocryptfs /srv/data-cipher /srv/data-plain
Two commands, no container sizing, no root privileges. Reverse mode inverts this and is genuinely useful for producing encrypted backups of an existing plaintext tree.
Where it fits
- Private use
- An encrypted subdirectory in a home folder on a shared or multi-user machine.
- Business use
- Encrypting a data directory on a server where the underlying volume is managed by someone else, such as a hosting provider, a managed Kubernetes node pool, or a backup target. It is also a sensible default for developer workstations handling client data extracts, because it composes with normal tooling rather than fighting it.
Back up the master key, not only the data
Losing the configuration file or the master key printed at initialisation means the data is unrecoverable. Store that key the way a recovery key is stored, separately from the ciphertext it protects.
What it gives you
- Authenticated encryption, so integrity is protected and not only confidentiality
- An independent 2017 audit, with findings tracked publicly
- Good speed on modern CPUs with AES-NI, and no fixed container size to manage
- Reverse mode for encrypted backups without duplicating storage
What it does not
- Conceal the directory structure, which is visible one-to-one in the ciphertext directory
- Perform acceptably over sshfs or CIFS, where rclone crypt is the better choice
- Ship a GUI or official Windows build, cppcryptfs being the closest equivalent
- Recover anything without the user’s own key backup
5. age
Status — August 2026
Actively maintained, version 1.3.x, with independent Rust and TypeScript implementations and a published format specification.
age is the newest tool on this list and the one most likely to change how an engineering team works. It is a single binary that encrypts a file to a recipient’s public key, and that public key is a 63-character string beginning with age1, short enough to paste into a ticket or a chat message. There are no options to misconfigure, because there are almost no options.
Generating a key and encrypting to a recipient
age-keygen -o key.txt
age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p \
-o extract.csv.age extract.csv
That is the entire interface. Most encryption failures in engineering contexts are configuration failures, and age removes the configuration surface.
It composes with UNIX pipes, which makes it the natural choice inside scripts, CI jobs and backup pipelines where the keyring model of GnuPG is a liability.
Where it fits
- Private use
- Encrypting backups before uploading them anywhere, or sending a file to a technical recipient without the overhead of a PGP key exchange.
- Business use
- Encrypting data extracts in automated pipelines, protecting secrets committed to repositories through SOPS, which supports age as a backend, and any workflow where a machine identity needs to encrypt to a human recipient. It also works with hardware tokens such as YubiKeys through a plugin, which is what makes it viable for high-value keys.
age does not authenticate the sender
Encryption and signing are separate problems, and age solves only the first. Where the origin of a file matters as much as its confidentiality, pair it with a signature mechanism or use GnuPG instead.
What it gives you
- A near-zero configuration surface, which is the single best security property a tool can have
- Keys small enough to live in environment variables and configuration files
- Multiple interoperable implementations, so it is not hostage to one codebase
- A natural fit for automation, secret management and backup encryption
What it does not
- Sign anything, so sender authenticity needs a separate mechanism
- Manage key lifecycle, with no expiry, revocation or web-of-trust equivalent
- Record who a file is for, which is a privacy feature and an operational nuisance
- Satisfy counterparties who contractually specify OpenPGP
6. GnuPG
Status — August 2026
Actively maintained. The 2.5 series is the current stable branch, with 2.5.21 released on 2 July 2026. The 2.4 series reached end of life on 30 June 2026.
GnuPG is the free implementation of the OpenPGP standard, and it remains the common language for encrypted file and email exchange between organisations that have never met. The headline development in the 2.5 series is the introduction of Kyber (ML-KEM, FIPS 203) as a post-quantum encryption algorithm.
It does the things age deliberately does not: signatures, key expiry, revocation certificates, subkeys, smartcard support and a trust model. Where a file needs to be provably from a specific party and unaltered, this is the mature answer.
Anyone still on GnuPG 2.4 is running end-of-life software
The 2.4 branch stopped receiving fixes on 30 June 2026. Check what is actually installed on servers, build agents and developer machines, because distribution packages often lag well behind upstream.
Where it fits
- Private use
- Verifying software signatures, something worth doing on every security tool downloaded, including the others on this list.
- Business use
- Automated file exchange with banks, insurers, payroll providers and public authorities, most of which still specify PGP. Also signing releases, signing commits and encrypting to a partner’s published key. Where personal data is exchanged with a processor under a data processing agreement, PGP is frequently the mechanism the contract already names.
What it gives you
- A complete key lifecycle: expiry, revocation, rotation and subkeys
- Signing and encryption in one system, with hardware smartcard support
- Post-quantum encryption in the current stable branch
- Universal acceptance in regulated business-to-business file exchange
What it does not
- Stay simple, since the command surface invites mistakes and the trust model resists explanation
- Sit comfortably in containers and CI runners, because of its keyring state
- Look after its own versioning, with branch end-of-life dates that need tracking
- Conceal recipients, whose key identifiers are visible in the ciphertext by default
7. 7-Zip
Status — August 2026
Actively maintained. Version 26.02 was released on 25 June 2026 and fixes CVE-2026-14266, a heap overflow in the XZ decoder present since version 21.07, alongside earlier fixes including CVE-2026-48095 in the NTFS handler.
7-Zip is an archiver first and an encryption tool second, and that is exactly why it earns a place: everyone already has it, or can install it in thirty seconds, which makes it the lowest-friction way to send an encrypted file to someone who will not install anything else.
Two settings decide whether this is real protection
Use the 7z format with AES-256, not the ZIP format’s legacy ZipCrypto, which is trivially broken. And enable file name encryption, because otherwise the contents of the archive are listed in plaintext, which can be the disclosure that matters when the file names themselves identify people.
A correctly configured archive
7z a -t7z -mhe=on -p archive.7z ./records/
The -mhe=on flag is the one that encrypts file names. Without it, the archive lists its own contents to anyone who opens it.
Checklist before sending
- 7z format, not ZIP
- File names encrypted (
-mhe=on) - Passphrase sent over a different channel than the file
- Recipient’s 7-Zip is on 26.02 or later
Where it fits
- Private use
- Sending documents to an accountant, a landlord or a family member.
- Business use
- One-off transfers to counterparties with no shared key infrastructure. It should be treated as a tactical measure rather than a process: anyone doing it weekly needs proper key-based exchange instead.
What it gives you
- Strong AES-256 encryption in the 7z format, including optional file name encryption
- Free, open-source software that is installed almost everywhere already
- No accounts, no servers and no vendor dependency
- Excellent compression, which is often why it is on the machine in the first place
What it does not
- Present a small attack surface, given a steady stream of memory corruption CVEs in its parsers
- Update itself, so unpatched installations persist for years across most fleets
- Manage keys, offering only passphrases with no rotation or revocation
- Warn you when misconfigured, since ZipCrypto and unencrypted file names both look like success
8. AxCrypt, and its open-source sibling Xecrets Ez
Status — August 2026
AxCrypt is actively developed as a commercial freemium product by AxCrypt AB. Xecrets Ez and Xecrets Cli, from the original author of AxCrypt at Axantum, are GPLv3, file-format compatible, and actively maintained.
This slot addresses a specific problem: getting non-technical colleagues to actually encrypt things. AxCrypt integrates into the file explorer so encryption is a right-click, and it handles the awkward part, which is opening an encrypted document, editing it, and re-encrypting on close, without the user thinking about it.
Two products, one file format
The original developer of AxCrypt left the company and now maintains Xecrets, which is fully interoperable with AxCrypt but has no server-side dependency and is free at the basic tier. Files encrypted with one open in the other. Where the account requirement is a concern, Xecrets is the same cryptography without it.
Where it fits
- Private use
- Individual documents on a shared family computer.
- Business use
- Small teams handling occasional confidential documents where deploying a full information rights management platform is disproportionate. It should be paired with a password manager so that passphrases are not written on notes.
What it gives you
- Right-click encryption and in-place editing of encrypted files
- Cross-platform support, with optional YubiKey use in Xecrets Ez
- An open-source cryptographic core with no publicly known vulnerabilities in the format
- A server-independent path through Xecrets where account dependency is a concern
What it does not
- Offer AES-256 for free in AxCrypt, where the free tier is AES-128 and account-based
- Work without servers in AxCrypt, whose key sharing depends on them
- Match the public audit record of VeraCrypt or Cryptomator
- Protect anything the user forgets to encrypt, since coverage is file by file
Tools that did not survive the review
The 2023 version of this article recommended three tools that should no longer be used. Naming them matters more than quietly deleting them, because installations persist long after projects die.
| Retired tool | Maintained | What happened | Replace with |
|---|---|---|---|
| Operations ceased 31 December 2025 | Cryptomator | ||
| Declared dormant by its author, May 2024 | gocryptfs, or rclone crypt for cloud | ||
| Sporadic development, fragmented ecosystem | age or 7-Zip | ||
| Abandoned 2014 | VeraCrypt |
Boxcryptor is gone, and so is access to anything it encrypted
Dropbox acquired key assets in late 2022, new registrations closed immediately, and Secomba GmbH ceased all operational activities on 31 December 2025. Anyone still holding Boxcryptor-encrypted data should decrypt it now, while a working client still exists on their machine. Cryptomator is the direct replacement, and is copyleft-licensed specifically so that this cannot happen to it.
EncFS is unsafe for exactly the use case it was popular for
A 2014 audit found that EncFS deviates from established standards, and one finding is fatal for cloud storage: it is not secure when an attacker can observe multiple versions of the same file over time, which is precisely what synchronisation produces. The author declared the project unmaintained in May 2024, and Linux distributions have been deprecating and removing it since. Migrate while a working build still exists to read the archives.
AES Crypt and TrueCrypt: not urgent, but not a foundation
AES Crypt still works and its format is sound, but it offers nothing that age or 7-Zip does not do better with far more maintenance behind it. TrueCrypt is unsupported, and VeraCrypt removed the ability to open TrueCrypt volumes in version 1.26.7, so legacy volumes now require an older VeraCrypt build to migrate.
The general lesson is worth stating plainly: a tool’s maintenance status is a security property. An unmaintained encryption tool does not fail loudly. It keeps working, keeps producing files that open, and quietly stops receiving the fixes that keep it safe. Reviewing the maintenance status of cryptographic tooling belongs in an annual control review, not in a blog post read once.
Where this sits in compliance obligations
For businesses, encryption is not only a good idea. It is specifically named across the frameworks that govern most organisations.
| Framework | Provision | What it means in practice |
|---|---|---|
| GDPR | Article 32(1)(a) | Encryption named as an example of an appropriate technical measure, judged against the state of the art |
| GDPR | Article 34(3)(a) | Communication to data subjects may not be required where data was rendered unintelligible |
| ISO/IEC 27001:2022 | Annex A 8.24 | Rules for the effective use of cryptography, including key management |
| NIS 2 | Article 21(2)(h) | Policies on the use of cryptography and, where appropriate, encryption |
State of the art is why running unmaintained tooling is a compliance problem and not only a technical one. And the Article 34(3)(a) exemption is the provision that repays the investment, but it comes with conditions: the obligation to notify the supervisory authority and document the breach still stands, and the exemption only holds if the keys were not also compromised.
Encryption at rest is not pseudonymisation
The two are distinct concepts under GDPR, and Article 4(5) sets a specific definition for pseudonymisation that encrypted storage does not automatically meet. Treating them as interchangeable is a common and expensive mistake in records of processing and DPIAs.
Two engineering points follow. The Article 34(3)(a) exemption depends on the keys being genuinely separate from the data: an encrypted database with the key on the same host, loaded into the same process, protects against disk theft and very little else. And auditors ask about key lifecycle far more than about algorithm choice, so a tool selection without a key management process behind it will not pass.
The mistakes worth avoiding
The single most common failure
Encrypting the data and storing the key beside it. Before signing off on any control from this list, ask where the key lives, who can reach it, and what happens if that person leaves.
- No recovery path
- Strong encryption without key escrow or a documented recovery procedure converts a minor incident into permanent data loss. Design the recovery path before deploying the control.
- Assuming at-rest encryption covers a live system
- Once the volume is mounted and the user is logged in, an attacker with code execution reads everything. At-rest encryption addresses theft, loss, disposal and physical access, not malware.
- Choosing a tool that users will route around
- A slightly weaker control that people actually use beats a stronger one they email around.
- Never revisiting the choice
- Every tool on this list has changed materially in three years.
Getting this right in practice
Tool selection is the easy part. The work is in the policy that governs when encryption is required, the key management process behind it, and the evidence that both are operating, which is what an ISO 27001 auditor, a customer security questionnaire or a supervisory authority will actually ask to see.
Up Secure works at exactly this intersection: privacy and security engineering that produces working controls, and GDPR and ISO 27001 advisory that turns them into defensible compliance. To work out which of these tools belongs in a given environment, get in touch.
Last reviewed: August 2026. Version numbers, maintenance status and vulnerability references reflect information available at the time of review. Encryption tooling changes quickly, so current release status should be verified before deployment.