35 working tools covering modern algorithms (AES-GCM, RSA-OAEP, ECDSA, Shamir secret sharing) and historical ciphers with real attack analysis (frequency analysis, Kasiski examination, Enigma simulation). Every tool runs against the Web Crypto API — when it says AES-GCM, it really is AES-GCM, not a renamed XOR.
They rename base64 as "encryption". They use ECB mode and call it AES. They show you a green checkmark even when the math is broken. We don't.
The Caesar tool actually runs chi-squared scoring against English. The Vigenère tool runs Kasiski examination and index of coincidence. The Enigma tool models rotors, reflectors, and plugboards — not a lookup table.
Every algorithm runs in your browser via the Web Crypto API or self-contained JavaScript. Open DevTools — you'll see no fetch requests to our servers. There are no servers.
Click any tool to open its dedicated page. Each page explains what the tool solves, who it's for, how to read the output, and where the math breaks down.
AES in real authenticated modes.
5 tools
RSA, ECDSA, ECDH — with key generation.
5 tools
SHA family, HMAC, PBKDF2, HKDF.
5 tools
Shamir, threshold reconstruction.
3 tools
Caesar, Vigenère, Playfair, Enigma…
8 tools
Base64/32/58, Hex, Morse, Braille.
5 tools
Zero-width chars, homoglyphs, LSB.
3 tools
JWT, X.509, traffic pattern checks.
1 tool
Every tool opens in a dedicated page with usage notes, FAQ, and limitations.
If you're new to cryptography, here's a sensible order. If you already know what you want, ignore this and click a tool.
Purpose. CipherLayer is a working cryptography workshop for people who want to understand what they're doing. We built it because the typical online "encryption tool" is either a black box or a renamed base64 encoder. Neither helps anyone actually learn.
Who it's for. Three audiences: students learning applied crypto (they need to see the math, not just click a button), engineers evaluating libraries (they need to know what mode they're using and why it matters), and curious people who want to know whether the tool they're about to trust is real or theater.
How it's built. Modern tools use the browser's Web Crypto API — the same primitive implementations that ship in Chrome and Firefox. Historical ciphers are implemented in self-contained JavaScript so you can read them line by line. There is no server. Open DevTools, watch the network tab, and notice the absence of requests.
What it does not do. It does not replace OpenSSL, libsodium, or a HSM. It does not generate keys it keeps on disk. It does not pretend a 56-bit DES key is a reasonable choice. It does not claim that encoding is encryption.
Limitations you should know. A browser is not a hardened crypto device. Side-channel attacks (cache timing, power analysis) are not mitigated. If your threat model includes a determined adversary with physical access to your machine, use a dedicated tool. For everything else — learning, prototyping, low-stakes message scrambling — this site is fine and explicit about its scope.
Maintenance. Tools are reviewed when browser APIs change. Algorithms are not silently downgraded. If a tool's behavior changes, the page says so.
Last updated:
Summary. CipherLayer does not collect, store, or transmit any personal data. All cryptographic operations run locally in your browser. We do not have a backend that receives your inputs.
This site may display ads served by Google AdSense or other third-party advertising networks. These networks use cookies to serve ads based on a user's prior visits to this site or other sites. Google's use of advertising cookies enables it and its partners to serve ads based on the visit to this site and/or other sites on the Internet.
Cookies are small text files placed on your device. CipherLayer itself does not set cookies. Third-party advertising networks (such as Google AdSense) may set cookies when they serve ads. You can control cookies through your browser settings.
When you use a tool on this site, the input you type stays in your browser. The page does not make a network request with your input. We have no way to read what you typed. We have no logs that contain it.
Our hosting provider may record standard HTTP request metadata (your IP address, requested URL, user agent, response code) for operational and security purposes. This is hosting infrastructure-level logging, not application logging, and is outside our control.
This site is not directed at children under 13. We do not knowingly collect information from children under 13.
We may update this policy. The "last updated" date at the top will reflect the change. Material changes will be visible on this page.
Questions about this policy should be directed through the contact mechanism provided by the site operator. We respond to legitimate privacy inquiries.
For reference and educational use only. The tools on this site are provided for educational, prototyping, and reference purposes. They are not a substitute for professional cryptography advice and must not be used as the sole safeguard for information that requires real protection.
CipherLayer does not provide legal, compliance, financial, or security consulting services. The presence of a tool on this site does not constitute a recommendation that the algorithm it implements is appropriate for your use case. Choosing cryptography is a context-dependent decision that should involve a qualified professional when stakes are non-trivial.
The tools are provided "as is" without warranty of any kind, express or implied. We do not warrant that the tools are error-free, that defects will be corrected, or that they will meet your requirements. Implementations of cryptographic algorithms may contain bugs. Side-channel resistance is not guaranteed.
All computation happens in your browser. This means the tool operator cannot see your data. It does not mean the tool is invulnerable to attacks against your browser, your machine, or your network. Malicious browser extensions, compromised devices, and network observers remain threats.
Do not use these tools to protect information where failure would cause significant harm (medical records, financial transactions, classified information, infrastructure access). Use established libraries (libsodium, OpenSSL, BoringSSL) integrated into audited systems for those purposes.
Some tools implement algorithms (such as classical ciphers) for educational reasons. Their presence on this site is not an endorsement of their use for protecting real information. The Caesar cipher has been broken since the 9th century. It is on this site because understanding why it fails is instructive.
To the maximum extent permitted by law, the site operator shall not be liable for any damages arising from use of, or inability to use, the tools provided.