Atlas of Systems Atlas
MMXXVI
cryptovaultno keypair
—
RSA-4096-OAEP + AES-256-GCM · Web Crypto API · nothing here is simulated

CryptoVault

Hybrid encryption in a single HTML file. No server, no dependency, no network call — the browser's own crypto engine and nothing else.

Web Crypto API · RSA-4096-OAEP · AES-256-GCM
status: dormant — the primitives below still run cold, nothing here has rotted
// full console · rsa-4096 + aes-256-gcm Open CryptoVault → Generate · encrypt · decrypt · copy the packet · SHA-512 OAEP
keys never leave the tabthe demo above is the short version
CryptoVault — a look inside, on desktop and phone
inside the app · desktop and phone
Why hybrid

RSA can't encrypt your message

A 4096-bit RSA-OAEP key can encrypt about 446 bytes. That's a sentence, not a document. So RSA never touches the message at all — it encrypts a key, and that key encrypts the message.

01
Generate a fresh AES-256 key

New random key per message. It exists for one encryption and is never reused, so a compromised message compromises nothing else.

02
Encrypt the payload with AES-GCM

Fast, handles any size, and GCM is authenticated — tampering is detected on decrypt rather than silently producing garbage.

03
Encrypt the AES key with RSA-OAEP

256 bytes of key material, comfortably inside RSA's limit. This is the only thing the asymmetric layer ever sees.

04
Ship both together

The wrapped key, the IV, and the ciphertext travel as one blob. Only the private key holder can unwrap step three and therefore step two.

The console above does all four steps for real, in your browser, using crypto.subtle. The ciphertext it prints is the actual output — not a stand-in.

The constraint

One file, zero trust in me

Every design decision follows from a single rule: someone should be able to read the whole thing before using it, and verify there's nothing else in it.

No dependencies

No npm tree, no CDN, no crypto library to audit. Web Crypto is the browser's, already reviewed by people better at this than either of us.

No network

Nothing is fetched and nothing is posted. Open devtools, watch the network tab stay empty, and you've verified the core claim yourself.

No storage

Keys live in memory for the tab's lifetime. Close it and they're gone — which is a feature and an obvious footgun at the same time.

Readable

One file you can scroll to the bottom of. That's the entire security argument, and it only works if it stays small.

Honest limits

What this doesn't do

No key distribution

Getting a public key to the other person safely is the actual hard problem in all of cryptography, and this file doesn't touch it.

No identity

Encryption proves nobody else can read it. It does not prove who sent it. That needs signatures, which is a separate mechanism.

Delivery is the weak point

If the page is served over the network, whoever serves it can change it. Local file or nothing.

Not a replacement

For anything that genuinely matters, use age or GPG. This is a working demonstration of the primitives, not audited infrastructure.

A crypto tool that overstates itself is worse than no tool. The limits above belong in the interface, not in a README nobody opens.