Back

Wyncrypt

A command-line tool that turns a folder of files into a single encrypted file. Rolling everything into one archive first is the point: the filenames, the folder structure and the file count end up inside the ciphertext rather than beside it.

Role
Designer and sole builder
Year
2026
Scope
Command-line tool · file encryption
Status
In development, not published

01What it is

You collect whatever you want protected into a single staging folder, run one command, and get back one encrypted file. It is safe to put on a USB stick or upload to cloud storage. Unlocking reverses it, back into a folder.

There is no configuration, no daemon and no interface. It uses only the cryptography Node already ships with, so there is nothing to compile and no native dependency to install.

02Why it rolls everything into one file

Encrypting files where they sit protects the contents and leaves everything around them in the open: the filenames, the folder structure, how many files there are. That is frequently the part that gives you away. A folder named for a medical condition with twelve files in it has told the story before anyone decrypts anything.

Rolling everything into one archive before encrypting puts all of that inside the ciphertext. What is left on disk is a single file whose name you chose, and whose size is the only thing it discloses.

It also makes the crash-safety story simple. Nothing is deleted until the encrypted file has been written, flushed to disk, and read back and verified in full. If any step fails, the originals are still exactly where you left them.

03What it does not protect

Once the encrypted file exists, its contents are safe at rest. What the tool cannot promise is that the originals are gone. It overwrites the staged files before removing them, but overwriting logical blocks does not reach data the storage layer has already moved: SSDs relocate writes for wear levelling, copy-on-write filesystems write to new blocks by design, and snapshots, backups and cloud sync keep copies of their own.

It also cannot reach a backup taken before you staged a file, and it cannot help on a machine that is already compromised, where anything that asks you to type a password is defeated anyway.

So it is a layer on top of full-disk encryption rather than a replacement for it, and the documentation says so in those words. A tool in this category that overstates its reach is worse than one that does not exist.

Other case studies

Back to work