End-to-end encryption, ready for the post-quantum era.

Encrypt in your browser, with keys that never leave your device — or the HSM. Classical and post-quantum certificates issued by a hardware-anchored CA.

Already have an account? Sign in

zero-knowledge post-quantum cryptography Technology 100% developed in Brazil · Five-Eyes free

See it in 90 seconds

The security that protects a nation, now with you.

We move trust from the server to the math

TRADITIONAL MODEL · SERVER-SIDE

The server receives and processes files in the clear. A single vulnerability exposes the whole operation.

CLOUDCRYPT · ZERO-KNOWLEDGE

The server receives only the encrypted package, without the key to open it. Server breached: your data stays protected.

  1. Encrypt in the browser

    The key is born and stays on your device. The file is encrypted before anything is sent.

  2. Store only the encrypted blob

    The server keeps only encrypted packages — never the key to open them.

  3. Share with proof

    Every container has an audit trail: sent, accessed, decrypted — with date and time.

Why CloudCrypt?

Client-Side Encryption

Your files are encrypted in your browser before transmission. Private keys never leave your device.

Post-Quantum Cryptography

ML-KEM-1024 and ML-DSA-87 — the NIST FIPS 203/204 standards. Protect today what must remain secret decades from now.

Keys in Hardware

CA and user keys generated and held in a kNET HSM, or on a KeyGuardian USB token — private keys never exist outside the hardware.

Certificate-Based Trust

Dual certificate chains — classical (ECDSA) and post-quantum (ML-DSA) — rooted in a hardware-anchored Certificate Authority.

Flexible Multi-Factor Authentication

Configurable MFA: Password, TOTP, WebAuthn, Email codes. You choose your security level.

Corporate Control

M-of-N escrow recovery protected by an HSM quorum, delivery tracking and digital signatures on every container.

Built for Security

CloudCrypt uses standardized cryptography: AES-256, ECDH/ECDSA P-256, ML-KEM-1024 and ML-DSA-87 (NIST FIPS 203/204), and Argon2id password hashing. Dual CA chain anchored in an HSM. CloudCrypt is a KRYPTUS product.

From personal to enterprise

Personal

Free

For individuals and small teams that need to exchange files securely.

  • Zero-knowledge encryption in the browser
  • ECC suite, configurable MFA
  • Certificate-based recipients
Create Personal Account

"Trust is not requested, it is proven. We bring to your daily life the same cryptography that protects the country's sovereignty."

Dr. Roberto Gallo Dr. Roberto Gallo · CEO and Founder, Kryptus

23 years protecting what matters most

CloudCrypt is built by Kryptus, a cryptography and cybersecurity company with the same root of trust that underpins the country's critical infrastructure — from voting machines to national defense.

From electronic voting machines to national defense
BSI certified: ISO 9001, ISO/IEC 27001, 27701, 20000-1 NIST post-quantum algorithms validated
23years in operation
20+countries with presence
ICP-Brasil100% of digital certificates issued in Brazil depend on the kNET HSM
Gov.br600k+ digital signatures protected by Kryptus every day

Aligned with BCB 538/2025, CMN 5274/2025 and PCI DSS 4.0.1 when operated on Kryptus infrastructure.