PART 09 · 🟡

Encrypted storage

Proton Drive

🟢 BeginnerReplaces Google Drive / iCloud🇨🇭 · E2EEFree + paid plan

What it's for

An end-to-end encrypted cloud for your files and photos, part of Proton.

Why it matters

Unlike Google Drive or iCloud, Proton can’t read your files: they’re encrypted before leaving your device. Swiss jurisdiction, same account as Proton Mail.

For whom & when

Everyone, as a simple, direct replacement for Google’s or Apple’s cloud.

Install & use
  1. Enable Proton Drive in your Proton account and install the app.
  2. Turn on automatic photo backup, then disable Google’s/Apple’s.

Cryptomator

🟡 IntermediateEncrypt before upload🇩🇪 · open-sourceFree + paid plan

What it's for

A vault that encrypts your files before uploading them to any cloud, even Google Drive or Dropbox.

Why it matters

The perfect trick if you must keep an existing cloud: you keep the convenient service, but the provider only sees encrypted gibberish. You alone hold the key.

For whom & when

Those who can’t leave a mainstream cloud yet, but want to protect their files right now.

Install & use
  1. Install Cryptomator (desktop and mobile) from cryptomator.org.
  2. Create a “vault” in your cloud’s synced folder, choose a strong password.
  3. Put your files in the vault: they’re encrypted then synced automatically.

VeraCrypt

🟡 IntermediateReplaces BitLocker🌍 · open-sourceFree

What it's for

The reference for local encryption: a whole disk, a partition, a USB stick, or an encrypted container (a file that mounts like a drive).

Why it matters

Nothing leaves your machine: no account, no cloud, no recovery key sent to a vendor. Free, audited, the successor of TrueCrypt. It is the local counterpart of Cryptomator, which is designed for the cloud.

For whom & when

On Windows, to replace BitLocker; everywhere, for an encrypted container or external drive. On Linux and macOS, the built-in encryption (LUKS, FileVault) is enough for the system disk.

System encryption and Secure Boot

In 2026 Microsoft is revoking the 2011 UEFI certificate authority that signed the old bootloader. If you encrypt the system disk, use version 1.26.29 or later, which ships bootloaders signed for both the 2011 and 2023 authorities.

Install & use
  1. Download VeraCrypt from veracrypt.jp and check the file’s PGP signature or checksum.

  2. Create a volume with the default settings (AES, SHA-512); Argon2id is offered since version 1.26.29.

  3. Choose a long passphrase (several random words), never reused.
  4. Advanced: create a hidden volume inside the volume for plausible deniability.

Nextcloud

🔴 AdvancedYour own cloud🌍 · open-sourceFree

What it's for

Your own cloud (files, calendar, contacts, notes) hosted on your server.

Why it matters

The ultimate degree of control: your data never leaves your hardware. Detailed in section 10 (Self-hosting).

For whom & when Self-hosters. See the full card in section 10.

Not sure where to start? Take the 12-question quiz →