Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

There is no single best encryption app for every kind of data. For a lost or stolen computer, start with the encryption built into its operating system: BitLocker or Device Encryption on supported Windows devices, FileVault on Mac, and LUKS on Linux. Use Cryptomator for selected files in cloud storage, VeraCrypt for portable encrypted containers, and a dedicated password manager for credentials.

The right choice depends on what you need to protect, where it is stored, and how you will recover it if a password or key is lost. Encryption is useful only when the recovery plan and backups are sound.

Choose encryption by what you need to protect

Your need Good starting point What it protects
Protect a computer if it is lost or stolen BitLocker or Device Encryption on supported Windows devices; FileVault on Mac; LUKS on Linux A disk or volume, principally against offline access
Protect a USB drive or portable container VeraCrypt or an encrypted volume supported by your operating system Selected files or a removable volume while it is locked
Protect files in cloud storage Cryptomator Files encrypted on your device before they sync
Protect passwords and passkeys Bitwarden, 1Password, or Proton Pass Credentials stored in a password vault
Send a few protected documents An encrypted archive or secure file-sharing service A particular package of files or shared link
Protect communications An end-to-end encrypted messaging or email service Message content, subject to the service’s coverage and limits
Manage protection across a business fleet A centrally managed endpoint or data-protection platform Devices and data under organizational policies

These are different layers, not interchangeable products. NIST’s guidance distinguishes full-disk, volume, virtual-disk, and file or folder encryption because each fits different risks and workflows: NIST SP 800-111.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What encryption protects—and what it does not

Encryption turns readable information into ciphertext that requires the right key to recover. Its protection depends on what is encrypted, whether the volume is locked, where the key is kept, and whether an attacker can access the running device. A properly encrypted disk can make data unreadable to someone who steals the powered-off computer or removes its drive. An encrypted cloud vault can keep a storage provider from reading file contents, depending on the product’s design.

#1 Best Overall
  • It can help against: offline access to a stolen device or locked removable drive; exposure of selected files stored in an encrypted vault; and interception of properly implemented end-to-end encrypted communications.
  • It does not automatically stop: malware or ransomware accessing files while a user is logged in; phishing, stolen account credentials, keyloggers, or screen capture; a recipient copying a file after opening it; or disclosure from an unencrypted backup or USB drive.
  • It may not hide metadata: depending on the tool, names, sizes, timestamps, account details, access timing, and network traffic can remain visible.

Full-disk encryption is principally a defense for data at rest. Once you unlock the computer, applications and malware running in your account may be able to read files. Locking, sleeping, hibernating, and shutting down are not necessarily equivalent: a sleeping device may retain keys in memory, depending on the hardware and platform.

Built-in encryption for the whole computer

Windows: BitLocker or Device Encryption

BitLocker is Microsoft’s built-in full-drive encryption feature. Availability and management options depend on Windows edition, device configuration, and organizational policy; some devices offer Device Encryption without the full BitLocker management interface. Microsoft says BitLocker recovery commonly uses a unique 48-digit recovery key. Check Microsoft’s BitLocker overview and its compatibility and recovery FAQ for the conditions that apply to your device.

For a personal laptop, TPM-backed protection is generally the practical default when supported. Keep the recovery key somewhere you can reach without the computer; a Windows sign-in password is not a substitute for a separately available recovery key. Firmware, hardware, boot, or policy changes can trigger a recovery prompt.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Check your Windows edition and whether BitLocker or Device Encryption is available. Use the Windows Settings search for “Device encryption” or “BitLocker,” or open the BitLocker management interface if your edition provides it.
  2. Back up important files before changing encryption settings.
  3. Turn on the available encryption option and follow its prompts.
  4. Save the recovery key outside the laptop, then verify that it is readable and associated with the correct device.
  5. Restart and confirm the encryption status in Windows.
  6. Keep a separate backup; encryption does not provide a backup.

If a recovery screen appears, use the saved key rather than repeatedly guessing credentials or erasing the drive. If you disable encryption while troubleshooting, make sure it is re-enabled afterward. Do not assume files synchronized to OneDrive or another cloud service are automatically encrypted in a way that prevents the provider from accessing them.

Rank #2
Sale
Bitdefender Total Security - 5 Devices | 1 year Subscription | PC/Mac | Activation Code by email
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows, Mac OS, iOS, and Android. Organize and keep your digital life safe from hackers.
  • ADVANCED THREAT DEFENSE: Your software is always up-to-date to defend against the latest attacks, and includes: complete real-time data protection, multi-layer malware, ransomware, cryptomining, phishing, fraud, and spam protection, and more.
  • SUPERIOR PRIVACY PROTECTION: including a dedicated safe online banking browser, microphone monitor, webcam protection, anti-tracker, file shredder, parental controls, privacy firewall, anti-theft protection, social network protection, and more.
  • TOP-TIER PERFORMANCE: Bitdefender technology provides near-zero impact on your computer’s hardware, including: Autopilot security advisor, auto-adaptive performance technology, game/movie/work modes, OneClick Optimizer, battery mode, and more

Mac: FileVault

FileVault encrypts a Mac’s startup disk; it is not a general-purpose tool for sharing individual files. Apple silicon and T2-equipped Macs include hardware-assisted security features, but recovery still depends on the method selected and on keeping the necessary credentials or recovery information. Follow Apple’s FileVault guide and do not assume Apple or a cloud account can reconstruct a lost recovery key.

  1. Open System Settings and search for “FileVault” (the exact location can vary by macOS version).
  2. Turn on FileVault and follow the offered recovery options.
  3. Record the recovery information using the chosen method and store it separately from the Mac.
  4. Confirm the startup disk is encrypted.
  5. Encrypt sensitive external drives separately and maintain an encrypted, versioned backup.

FileVault protects a locked or powered-off Mac against offline reading; it does not protect files from malware operating in an unlocked session.

Linux: LUKS and dm-crypt

LUKS, commonly used with dm-crypt, provides Linux disk and volume encryption. Setup and recovery depend on the distribution, installer, and boot configuration, so use the instructions for your specific system alongside the cryptsetup/LUKS documentation. Store passphrases and any recovery material safely, and include encrypted volumes in restore testing. Avoid assuming a procedure for one distribution will work unchanged on another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Tools for selected files, drives, and cloud storage

VeraCrypt: portable containers and removable media

VeraCrypt is free, open-source software for encrypted containers, partitions, and drives across Windows, macOS, and Linux. It is useful when you want a portable volume that you mount to work with and dismount afterward. It is more technical than built-in disk encryption and less convenient for frequently synchronized cloud folders.

While a VeraCrypt volume is mounted, its files are accessible to the user session and software running there. A forgotten passphrase or damaged container can make its contents unavailable. Keep a separate, unmounted backup of the container; where applicable, back up its header as well. Privacy Guides discusses VeraCrypt and operating-system alternatives in its encryption recommendations.

  1. Download the installer from the official VeraCrypt downloads page, and verify it when practical.
  2. Create a long, unique passphrase and choose a container size that allows for growth.
  3. Keep a backup outside the working container and test mounting that backup on another supported system.
  4. Dismount the volume before shutdown, sleep, or moving the drive.
  5. Avoid putting frequently changing files or active databases in a container that is also being synchronized unless you have tested that workflow carefully.

Cryptomator: files in cloud folders

Cryptomator encrypts files individually in a vault before they are stored in a synchronized folder. That file-based approach is often more practical than syncing one large VeraCrypt container. It can suit documents in services such as Dropbox, Google Drive, OneDrive, or iCloud Drive, but the cloud provider can still see account information, timing, file sizes, and network activity. Some filesystem-related details may also remain visible, depending on configuration and platform.

  1. Install Cryptomator from its official product page and create a vault in a locally synchronized cloud folder.
  2. Set a long, unique vault password and keep recovery information separate from the vault.
  3. Let the first synchronization finish, then open and close a test document from another supported device.
  4. Keep an independent backup outside the live synchronized folder.
  5. Wait for sync to finish before shutting down or switching devices; resolve conflicts carefully rather than deleting unfamiliar files.

Concurrent edits can create conflicts, and mobile support varies by provider and workflow. Confirm that your cloud client and desired offline access are supported before relying on a vault across devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Archives and individual document encryption

An encrypted archive can be a practical way to send a small group of files, and modern document formats may offer their own encryption options. For an archive, use a maintained tool such as 7-Zip, choose a strong unique password, and send that password through a separate channel. Confirm the recipient can open the archive before sending the only copy. The recipient’s device and any files they extract are outside your control.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Avoid relying on weak legacy document formats. The actual protection depends on the format and application version; do not assume that every file labeled “password protected” uses strong encryption.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Password managers protect credentials, not whole disks

A password manager is a separate category from disk encryption. It stores passwords, passkeys, and sometimes secure notes in a vault; it does not encrypt a laptop’s entire drive or substitute for a cloud-file vault. Choose one with a recovery model you understand, use a unique master password, and enable multifactor authentication where available.

Manager Potential fit Security and trade-offs
Bitwarden Users seeking cross-platform use, an open-source ecosystem, or the option of self-hosting Bitwarden describes its vault as using a zero-knowledge model. Self-hosting makes you responsible for updates, uptime, backups, and recovery. Current plan prices and feature limits should be checked on its pricing page.
1Password Families and teams that value sharing and administrative workflows 1Password documents AES-GCM-256 vault encryption and an account model involving credentials and an additional Secret Key. It is a managed commercial service; plan details are on its plans page.
Proton Pass Users in the Proton ecosystem or those seeking a cloud-based manager with a free tier Proton says Pass uses end-to-end encryption and AES-256-GCM for vault data, and describes its apps as open source and independently audited. Its free tier includes unlimited logins, notes, credit cards, devices, passkeys, and password generation, plus a limited number of hide-my-email aliases; features differ by paid plan. See Proton Pass pricing.

“Zero knowledge” and “end-to-end encrypted” describe a provider’s architecture, not a guarantee against a compromised device, account takeover, or every form of metadata exposure. Open-source code can be inspected, but that alone does not prove that every release is secure. Self-hosting can reduce reliance on a hosted provider while adding operational responsibilities; it is not automatically safer for a nontechnical household.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For any manager, create a unique master password, enable multifactor authentication, import credentials, verify the import, and then remove any plaintext export. Replace reused or exposed passwords and store emergency or recovery information safely. If you export backups, protect them as sensitive data and test that they can be restored.

Best Value
WinZip 30 | File Management, Encryption & Compression Software [PC Download]
  • Save time and space: With efficient file compression and duplicate file detection, you can store, open, zip, and encrypt; keep your computer organized and simplify time-consuming tasks
  • Protect your data: Password-protect important files and secure them with easy-to-use encryption capabilities like military-grade AES 256-bit encryption
  • Easy file sharing: Shrink files to create smaller, safer email attachments, then share directly from WinZip to social media, email, IM or popular cloud storage providers
  • Open any format: Compatible with all major formats to open, view, zip, or share. Compression formats include Zip, Zipx, RAR, 7z, TAR, GZIP, VHD, XZ, POSIX TAR and more
  • Manage your files in one place: Access, organize, and manage your files on your computer, network, or cloud service

Match the tool to the scenario

  • Lost-laptop protection: use the operating system’s full-disk encryption and keep its recovery key separately.
  • Family computer: turn on built-in disk encryption, use separate accounts and access controls, and maintain backups. A shared login weakens practical separation between users.
  • USB drive: use an encrypted volume compatible with the computers that need to open it. VeraCrypt offers cross-platform containers; check recipient compatibility first.
  • Cloud documents: use Cryptomator when you want to encrypt selected files before synchronization, and preserve an independent backup.
  • Passwords: use a dedicated password manager rather than a plain-text file or generic archive.
  • Small business: consider centrally managed endpoint encryption and identity controls so administrators can apply policy and plan recovery across devices. A consumer container tool is not a fleet-management system.
  • High-risk privacy use: define whether the concern is device theft, account compromise, a provider, or targeted access. Encryption at rest alone does not address every threat.
  • One sensitive file: use a secure sharing service or encrypted archive, share the password separately, and verify delivery without treating the recipient’s device as protected.

Recovery and backups are part of encryption

Strong encryption can make recovery impossible when the required key is lost. For some products, the provider cannot decrypt the data; that can limit provider access but makes your recovery plan your responsibility. Before enabling encryption, identify the recovery key or password, where it is generated, whether it can be exported, and what happens if the account or device is unavailable.

  • Keep recovery material separate from the encrypted device or vault it unlocks.
  • Maintain at least one separate backup, with another copy in a physically or logically distinct location when appropriate.
  • Protect backup drives and cloud copies too; an encrypted laptop does not encrypt an external drive by association.
  • Prefer versioned backups where available, which can help recover from deletion, corruption, or ransomware.
  • Test a restore periodically. A backup that has never been restored is unproven.
  • For VeraCrypt or other containers, test a copy rather than experimenting on the only live container.
  • For shared files, test access with the intended recipient before sending the only copy.

Encryption does not provide redundancy. It can protect confidentiality while leaving deletion, drive failure, sync errors, and damaged containers unresolved.

Common mistakes and limitations

  • Confusing an unlocked device with a protected one: full-disk encryption does not normally block software or people with access to an already unlocked session.
  • Encrypting the laptop but not its backups: removable drives and exported files need their own protection.
  • Assuming all cloud data is private: a sync service can still observe account and traffic metadata even when it cannot read vault contents.
  • Deleting files during a sync problem: an unfamiliar Cryptomator file may be part of the vault; back up first and resolve the conflict rather than guessing.
  • Using a container without testing recovery: a forgotten password or damaged container can block access to many files at once.
  • Thinking device encryption stops ransomware: ransomware can encrypt files the logged-in user can access. Versioned backups and cautious account use remain important.
  • Choosing by algorithm label alone: AES-256 or another modern cipher does not tell you whether key management, authenticated encryption, updates, recovery, and metadata protection are suitable.
  • Treating hardware encryption as automatically safer: implementation, firmware, authentication, and recovery still matter.

For more specialized communication needs, consult the service’s own technical documentation, such as Signal’s security documentation for messaging or Proton Mail’s guidance on encryption keys. Message and email encryption have their own trade-offs and do not replace protecting device storage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.