Tools / SwatCrypt

Security

SwatCrypt

Trust nothing. Wipe everything.

XChaCha20-Poly1305 STREAM encryption with memory-hard Argon2id key derivation, wrapping one or many files and folders into a single tamper-evident .swc bundle from a GUI or scriptable CLI with per-user Explorer context menus — single portable .exe, no admin.

Rustegui portable exe

Under the hood

XChaCha20-Poly1305 STREAM cipher

Encrypts the payload as a STREAM of chunks under a 192-bit nonce, eliminating nonce-reuse risk, and authenticates the plaintext header as AAD so any tampering fails decryption.

Argon2id key derivation

Derives the key from your passphrase with Argon2id at 64 MiB memory, 3 iterations, and parallelism 1 — memory-hard against GPU cracking — and stores nothing in a keyring.

Single authenticated .swc bundle

Packs one or many files and folders into a manifest plus tar stream, optionally gzip-compressed, inside one .swc file, preserving relative paths and rejecting symlinks.

Operating system
Windows

Distribution Single portable .exe — no installer, no admin rights required.

Dependencies None. Runs offline, zero telemetry.

Licence MIT · free forever

Encrypting files is easy to get subtly wrong, so SwatCrypt picks defaults that close off whole categories of mistake rather than offering a menu of footguns. It wraps one or many files into a single .swc bundle using XChaCha20-Poly1305 — the 192-bit nonce means you can stop worrying about nonce reuse — and derives the key from your passphrase with Argon2id. There’s a GUI for everyday use and a CLI for scripting and inspecting headers, and the application code is compiled with #![forbid(unsafe_code)] so the crypto can’t be broken by a stray unsafe block here.

Security model

Defaults:

  • cipher: XChaCha20-Poly1305
  • KDF: Argon2id
  • KDF memory: 64 MiB
  • KDF iterations: 3
  • KDF parallelism: 1
  • bundle format: one .swc file containing a manifest and tar stream
  • optional gzip compression, off by default
  • symlinks rejected
  • tamper detection through AEAD authentication

SwatCrypt does not store passphrases in a keyring. If you lose the passphrase, the data cannot be decrypted.

What it does

  • Encrypts a single file.
  • Encrypts multiple files into one bundle.
  • Encrypts folders while preserving relative paths.
  • Decrypts .swc bundles to an output directory.
  • Optionally compresses before encryption.
  • Can wipe originals after verify-decrypt.
  • Shows progress in both GUI and CLI modes.
  • Adds Windows Explorer integration from an in-app toggle.

Install

Download the latest release from:

https://github.com/Swatto86/SwatCrypt/releases

Run swatcrypt.exe with no arguments to launch the GUI.

GUI workflow

  1. Open SwatCrypt.
  2. Choose files or folders.
  3. Choose encrypt or decrypt.
  4. Enter and confirm the passphrase.
  5. Choose whether to enable compression.
  6. Choose output path.
  7. Start the operation and watch progress.

Encryption defaults to <input>.swc for a single input or bundle.swc for multiple selections. Decryption defaults to a <cipher>_dec output directory.

CLI commands

Launch GUI:

swatcrypt

Encrypt:

swatcrypt encrypt path/to/file.txt

Decrypt:

swatcrypt decrypt path/to/file.swc

Show header information without decrypting:

swatcrypt info path/to/file.swc

CLI options

Encrypt options:

OptionPurpose
--output <file>Output .swc path
--compressCompress before encryption
--passphrase <pw>Provide passphrase non-interactively
--chunk-size <bytes>Encryption chunk size
--forceOverwrite existing output
--wipeWipe originals after successful verify-decrypt

Decrypt options:

OptionPurpose
--output <dir>Output directory
--passphrase <pw>Provide passphrase non-interactively
--forceOverwrite existing output

Prefer interactive passphrase entry unless you understand the shell-history and process-list risks of passing secrets on the command line.

Explorer integration

On Windows, open the GUI and use Integration to install or remove per-user context menu entries. This uses HKCU keys and does not require administrator rights.

The context menu adds:

  • Decrypt with SwatCrypt for .swc files
  • Open in SwatCrypt for launching the GUI with selected items pre-filled

Format overview

The .swc file contains a plaintext authenticated header and an encrypted payload. The payload contains a manifest plus a tar stream, optionally gzip-compressed. The header is authenticated as additional data, so tampering is detected during decryption.

Build from source

git clone https://github.com/Swatto86/SwatCrypt.git
cd swatcrypt
cargo build --release

Run GUI:

cargo run

Run CLI:

cargo run -- encrypt path/to/file.txt

Troubleshooting

Decryption fails

Check the passphrase and confirm the file is a complete .swc bundle. Authentication failure can mean wrong passphrase or file corruption/tampering.

Output already exists

Choose a different output path or use --force when you intentionally want to overwrite.

Explorer menu is missing

Open the GUI and use the Integration toggle again. On Windows 11, check the extended context menu.

  • GitHub: https://github.com/Swatto86/SwatCrypt
  • Releases: https://github.com/Swatto86/SwatCrypt/releases