AES-256-GCM Authenticated Encryption
NIST-standard AES-256-GCM provides both confidentiality and integrity. Any tampering with the ciphertext is detected immediately during decryption.
MiWen delivers military-grade encryption for your text. Multi-layer encryption with transport obfuscation, passwords that never leave your control, expiry self-destruct and burn-after-reading — all done right in your browser.
Everything is processed server-side over an encrypted channel. Passwords and plaintext are never stored.
Every design decision serves one goal: even if the ciphertext and the server are fully exposed, your text remains safe.
NIST-standard AES-256-GCM provides both confidentiality and integrity. Any tampering with the ciphertext is detected immediately during decryption.
Passwords are stretched with up to 600,000 PBKDF2-SHA256 iterations, each layer using an independent random salt — brute force and rainbow tables become impractical.
Strong and Extreme modes wrap your data in multiple independent encryption layers, each with its own salt, IV and derived key, plus transport obfuscation.
Your password exists only for the brief moment of the request. The server never logs, stores, or can recover your plaintext. Without the password, nobody can decrypt.
Set a decryption lifetime from 5 minutes to forever. Expired ciphertext is cryptographically dead; share links support expiry and burn-after-reading with no trace left.
Pure PHP with no database or third-party extensions. Clean, compact codebase — anyone can audit every line of the encryption logic.
Secure encryption in four steps
Enter your text and a password, or use the built-in high-entropy random password generator.
Fresh random salt and IV are generated, the key is stretched via high-iteration PBKDF2, and AES-256-GCM encrypts in multiple layers.
Choose a lifetime from 5 minutes to forever, and optionally enable transport obfuscation and burn-after-reading.
Copy the ciphertext or create a one-time link. Recipients decrypt with the password; expired or read content self-destructs.
No. MiWen is zero-knowledge: the server neither stores nor can reset your password. Keep it safe — ideally in a password manager.
Plaintext travels over an encrypted channel (HTTPS), lives in memory only for the instant of computation, and is never written to disk, logs or any database. You can also self-host the app in a trusted environment.
The expiry is embedded inside the authenticated envelope and cannot be tampered with. After expiry, nobody — including you — can decrypt. Server-side share records are also physically deleted.
No. Obfuscation permutes the ciphertext alphabet to evade signature-based scanning and identification; it provides no cryptographic security. Real protection comes entirely from AES-256 and key derivation.