Encrypt & Store
Each document is encrypted on your iPhone with AES-256-GCM; its key is wrapped with X-Wing (X25519 + ML-KEM-768).
How encryption works
When you encrypt a file, Qpher Vault:
- Generates a random 256-bit file key on your iPhone
- Encrypts the file with that key (AES-256-GCM)
- Asks Qpher's isolated key service for a one-time X-Wing shared secret and uses it to wrap the file key
- Uploads the encrypted file and the wrapped key to storage in the United States (Cloudflare R2)
- Clears the file key and the shared secret from memory
Private keys are generated and used only inside Qpher's isolated key service. No API can export them.
Encrypt a file
- On the Documents tab, tap + and choose Encrypt document
- Choose where the file comes from — Files, Camera, Photos or Scan Document — and pick it
- Sign this document is on by default; leave it on to sign the document in your name
- Tap Encrypt & Save. Qpher Vault encrypts the document on your iPhone and uploads it
Use the iOS share sheet to send a file from another app straight into Qpher Vault.
Badges
| Badge | Meaning |
|---|---|
| Protected | The document is encrypted and stored in your vault |
| Signed | A signature is on record for the document |
What you can encrypt
PDF, Word, Excel, images and most other files you can share from your iPhone, up to your plan's file-size limit.
Limits
Your plan sets your storage space, the largest file you can encrypt and how many documents you can encrypt each month. Settings shows your storage and how many encryptions you have left this month; plans and prices are under Settings → Plan & billing and on qpher.ai/vault.
Related Guides
- View & Decrypt — How to open your documents
- Sign Documents — Add a signature in your name
- Share Documents — Share documents with the people you choose