
CipherKem encrypts and decrypts your documents and folders for a specific recipient or group using post-quantum key encapsulation — entirely on your machine. No shared secret, no password exchange, no cloud. Your files and keys never leave your computer.
Envelope verification free forever · Unlimited encryption & decryption on every paid plan · No cloud
Get Started in Three Steps
From download to your first encrypted file.
Install CipherKem on the Microsoft Store for Windows 10 or 11. Envelope verification works immediately — free, no account needed. Find your Machine ID under Settings → License.
Choose a plan from Pricing below and click Subscribe Now. Complete payment on our secure Stripe checkout (card or PayNow). Then email your Stripe receipt + Machine ID to [email protected] — we reply with your cipherkem.lic within 1 business day.
Open cipherkem.lic in CipherKem (Settings → License → Browse), generate your CipherKem identity, exchange Contact Cards with your peers out-of-band, and start encrypting and decrypting files and folders — entirely offline.
What's Free. What Requires a Subscription.
Anyone can verify an envelope's sender authenticity forever — at zero cost. Encrypting, decrypting, and managing identities requires a subscription.
These work permanently, with or without a subscription.
Each requires an active subscription at the moment of use.
Protocol at a glance
Each user generates a keypair: ML-DSA-44 for signing + ML-KEM-768 for encapsulation (configurable to ML-KEM-512 or ML-KEM-1024). Stored as a .identity file. The public half is exported as a self-signed .card file to share with peers.
Share your .card file with a peer out-of-band (email, USB, QR). CipherKem prompts you to verify the card's fingerprint with the peer directly — a call or in-person confirmation — before trusting it.
The sender uses the recipient's KEM public key to encapsulate a shared secret (.envelope file). The envelope is signed with the sender's DSA key so the recipient can confirm who created the session.
Each file is encrypted with AES-256-GCM using a key derived from the session secret via HKDF. Produced as a .parcel file. The whole session folder — envelope + parcels — is sent to the recipient.
Pricing
Three plans. All include unlimited encryption and decryption, all three ML-KEM security levels, group broadcast support, and envelope verification free forever for every recipient. Licenses are per-machine.
Individual Monthly
Solo professionals · 1 machine
Billed monthly
Individual Annual
Solo professionals · 1 machine
Billed annually
Save 21% vs monthly
Business Annual
Teams · up to 5 machines
Billed annually
5 machines included
cipherkem.lic file within 1 business day.
Contact Us
For subscriptions, license transfers, or support — email us directly.
support at cipherplus dot ioTerms of Use — Summary
The full terms appear inside CipherKem on first launch. Below is a plain-language summary of the key points. Last updated: June 2026.
Envelope signature verification and group descriptor verification are free forever, as are deleting, activating, and exporting the Contact Card of an identity already on your machine. Generating a new identity, encrypting files or folders, decrypting parcels, and creating or signing groups each require an active subscription. The same license covers all paid operations — no separate purchase.
The right to verify envelope sender authenticity and group descriptor signatures is granted to all users permanently and unconditionally, regardless of license status. This right cannot be revoked.
All license purchases are FINAL. No refunds, exchanges, or money-back guarantees. Verify CipherKem works for you using the free envelope verification feature before subscribing.
Each license is personal, non-transferable, and bound to a single machine. To move a license to a new machine, email us with your old and new Machine IDs.
Your CipherKem identity is stored only on your machine. If you lose the identity file, CIPHERPLUS cannot recover it and you will be unable to decrypt any parcel addressed to that identity. Previously encrypted parcels addressed to a lost identity are unrecoverable. Back up your identity file immediately.
You are responsible for verifying the real-world identity of parties whose Contact Cards you import — confirm their fingerprint out-of-band (phone, video, in person) before relying on it for encryption.
CipherKem is provided "AS IS" without warranty of any kind. CIPHERPLUS makes no warranties regarding merchantability, fitness for a particular purpose, or non-infringement.
To the maximum extent permitted by applicable law, CIPHERPLUS PTE. LTD. shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of CipherKem.
You are solely responsible for the files you encrypt, the recipients you send them to, and ensuring your use of CipherKem complies with all applicable laws, including export controls and data-protection regulations.
CipherKem v1 uses Static KEM mode. The confidentiality of a decrypted parcel depends on the recipient's long-term private key remaining secret. A future compromise of that key could allow an adversary who recorded the original session to decrypt past parcels. Document this for any deployment requiring long-horizon confidentiality.
CipherKem uses NIST FIPS 203 (ML-KEM) and NIST FIPS 204 (ML-DSA), validated under NIST CAVP Certificate A7970. No cryptographic system can guarantee absolute security in all circumstances. Consult a qualified advisor for your specific needs.
These Terms are governed by the laws of the Republic of Singapore.