macOS 14 or later

Drop a file. Type a password. It’s encrypted.

No account, no cloud, no subscription, and no vault you have to trust. One window, two gestures, and three real ciphers doing the work underneath.

Bit Cloak window: drop a file, encrypt it with AES-256-GCM

Why Ultra is fully secure

Ultra is a strict superset of Standard. Same file format. Three ciphers, three unrelated keys. The outer layer cannot lower the floor below AES. It can only raise the ceiling.

Standard

AES-256-GCM → ISAAC⁺

Ultra

AES-256-GCM → ChaCha20-Poly1305 → ISAAC⁺

Each layer has its own job.

1

AES-256-GCM

Hardware-accelerated through Apple CryptoKit. It encrypts and authenticates. Change one bit of ciphertext and the tag fails.

2

ChaCha20-Poly1305

A different design family from AES. A break in one does not become a break in the other. Ultra places this between AES and the outer keystream.

3

ISAAC⁺

An outer keystream under an independent key. If ISAAC⁺ falls, the attacker still faces AES-256-GCM, exactly where they would have been without it.

AES-256-GCM, ChaCha20-Poly1305 and ISAAC+ cascade diagram

Independent keys. The Argon2id master key is expanded through HKDF-SHA256 with distinct labels. Recovering one subkey tells an attacker nothing about the others.

Authenticated end to end. Every chunk is AEAD. The header is bound as associated data. Flip the Ultra bit, reorder chunks, or cut the file short, and decryption fails.

Nothing leaves this Mac. The sandbox grants one entitlement: the file you choose. No network, no account, no telemetry.

No recovery, on purpose. There is no backdoor. Forget the password and the file is gone. The terms say so in full.

Every guess costs real memory.

Argon2id runs at RFC 9106 settings: 64 MiB, 3 iterations, 4 lanes. A GPU cracking farm becomes an expensive way to guess slowly. A wrong password is rejected before Bit Cloak ever asks where to save.

  • Argon2id, the memory-hard, side-channel-resistant hybrid mode.
  • The cost is written into each file, so a later version can raise it.
  • The salt is 16 fresh random bytes per file.
Password sheet with an Argon2id strength meter

40 GB in. Megabytes of RAM.

Files stream through the cipher in 1 MiB chunks, across every core your Mac has. Output goes to a temporary file and is renamed into place only after a clean write, so a crash or a force-quit never leaves a broken file behind.

  • Memory use stays bounded, whatever the file size.
  • Chunks are independent, so the work runs in parallel.
  • Crash-safe: write, fsync, rename.
Streaming encryption across CPU cores
Bit Cloak has no network access beyond the file you choose
If you forget your password, the file is gone.

That is what strong encryption means. There is no recovery key, no backdoor and no support line that can open it. The sandbox grants Bit Cloak exactly one entitlement: the file you choose.

⦸ No network access ⦸ No account ⦸ No telemetry ✓ One sandbox entitlement

On the Mac App Store.

One price, no subscription, updates included. Terms · Privacy

Get it on the Mac App Store