The Complete Client-Side Encryption Guide

Why server-based encryption fails and how true zero-knowledge architecture protects your data.

📥 Download Free PDF Whitepaper

💡 Quick Summary — What This Guide Covers

Client-side encryption encrypts your files inside your browser using the Web Crypto API (AES-256-GCM), before they ever touch a network. UniDoc uses PBKDF2-SHA256 with 150,000 iterations for key derivation and OPFS chunking to process any file size without RAM limits.

  • Zero-Knowledge: UniDoc never receives your file, password, or encryption key — ever.
  • No File Size Limit: 2 MB chunks streamed via OPFS directly to the browser's crypto engine.
  • Server Risk: Cloud providers who hold your keys have been breached at scale — Yahoo (3B accounts), LastPass (33M users), MOVEit (77M+ records).
  • Algorithm: AES-256-GCM — approved by NSA for top-secret classified data.
  • Free tool: unidocapp.com/web_encrypt — no account, no installation.

📊 The Scale of the Server Encryption Problem

Data breaches are accelerating year-over-year. In every major incident, the root cause is the same: encryption keys stored on the same servers as the encrypted data.

3,205
Disclosed data breaches in 2023 — a 72% all-time high (ITRC)
$4.88M
Average cost of a data breach in 2024 (IBM Report)
194 days
Average time to detect a breach after it occurs
CompanyYearRecords ExposedRoot Cause
Yahoo2013–143 billion accountsServer breach; encryption keys stored server-side
Equifax2017147.9 millionUnencrypted data transiting internal servers
LastPass2022~33 million usersEncrypted vaults stolen together with key metadata
MOVEit202377+ millionSQL injection bypassed server-side encryption
AT&T202473 million customersKeys compromised separately from ciphertext
🚨

The pattern is always the same: the encryption key and the encrypted data live on the same server infrastructure. Once the server is compromised, the encryption becomes an illusion of security.

✅ Why Client-Side Encryption Is the Solution

Client-side encryption solves the fundamental architectural flaw. Your file is encrypted before it leaves your device. The server only ever receives ciphertext — and it never receives the key needed to decrypt it.

🔐

Zero-Knowledge Architecture: Even if UniDoc's entire infrastructure were compromised, there is literally nothing to steal — because we never possess your plaintext file, your password, or your encryption key.

How UniDoc Encrypts Your File — Step by Step

  1. Password + 32-byte Salt: Your password is combined with a cryptographically random 32-byte salt to prevent rainbow table attacks and ensure each file's key is unique.
  2. PBKDF2-SHA256 Key Derivation (150,000 iterations): Produces a hardened 256-bit encryption key from your password. Brute-force attacks become computationally infeasible.
  3. AES-256-GCM Encryption: The file is encrypted with a random 12-byte IV. GCM's authentication tag detects any tampering with the ciphertext on decryption.
  4. OPFS Chunked Streaming (2 MB/chunk): For large files, chunks are read from disk, encrypted, and written to the browser's OPFS sandbox — keeping peak RAM usage at ~4 MB.
  5. .enc Package Output: The salt, IV, version byte, authentication tag, and ciphertext are bundled into a single portable .enc file.

🗄️ How "No File Size Limit" Actually Works

Traditional browser encryption loads the entire file into RAM simultaneously, causing crashes for files above a few hundred MB. UniDoc avoids this using the Origin Private File System (OPFS) — a browser-native, sandboxed disk API.

⚡

Technical Detail: UniDoc reads the source file in 2 MB slices, encrypts each chunk with a per-chunk IV derived from the master IV XORed with the chunk index (preventing nonce reuse), writes the encrypted chunk to OPFS, and assembles the final .enc file from disk. Peak RAM usage: ~4 MB — whether the file is 100 KB or 100 GB.

📖 Read the Full Technical Whitepaper

The complete 18-page guide covers all topics in depth — including breach trend charts, a sequence diagram comparing server vs. client-side encryption, a real-world breach case study, and the full UniDoc cryptographic pipeline breakdown.

🎯 Key Takeaways

Encrypt Your First File — Free, Instantly

No account. No installation. No upload. Your file stays on your device from start to finish, protected by AES-256-GCM military-grade encryption.

🔐 Try UniDoc Client-Side Encryptor