de Deutsch en English fr Français es Español tr Türkçe ja 日本語 zh 中文 ar العربية ru Русский pt Português pk اردو id Bahasa Indonesia it Italiano kr 한국어 my Bahasa Melayu pl Polski se Svenska sg English (Singapore) gr Ελληνικά in हिन्दी
Shareware

Encryption of the
next generation

Three cryptographic protection layers. No cloud. No server. Fully offline. Your messages belong only to you.

Demo
▶ WATCH DEMO
2768
Possible keys
3
Protection layers
0
Servers / Cloud
10
Languages
History

From the broken machine to unbreakable encryption

The original Enigma machine, developed in the 1920s, was considered the most secure communication system of its time. The Wehrmacht used it millions of times in World War II – convinced the encryption was impenetrable. They were wrong.

Arthur Scherbius presents the Enigma

26 letters, rotating rotors, mechanical-electrical encryption. Initially rejected by the military, adopted by the German Navy from 1926. Scherbius did not live to see its success – he died in 1929 in an accident with his horse-drawn carriage.

Hans-Thilo Schmidt – the first betrayal

The German cipher bureau employee handed secret documents to French intelligence: an operating manual and key material. The French passed the information on to British and Polish services.

Marian Rejewski – the mathematical breakthrough

At the Polish Biuro Szyfrów (Cipher Bureau), Rejewski reconstructed the internal logic of Enigma through mathematical analysis – without ever having seen the machine. Together with Jerzy Różycki and Henryk Zygalski, he laid the groundwork for everything that followed.

Cyclometer & Zygalski Sheets

The Poles developed the Cyclometer for systematic key determination. Zygalski invented perforated paper sheets that made certain code properties visible when overlaid. When the Wehrmacht started changing keys daily from 1936, new methods were needed.

Bomba kryptologiczna

The world's first electromechanical decryption machine. It systematically tested possible keys – a revolutionary approach. But when the Germans introduced additional rotors, the Poles reached the limits of their resources.

Knowledge transfer at Pyry

Shortly before the war began, representatives of Poland, Britain and France met south of Warsaw. The Poles handed over machines, methods and all their findings. Without this step, Bletchley Park would have been impossible.

Alan Turing & Gordon Welchman – the British Bombe

As part of Operation Ultra, top secret at Bletchley Park under the codename Government Code and Cypher School, Turing and Welchman developed a far more powerful version of the Polish Bomba. The Bombe could not decrypt messages directly – but it drastically reduced possible keys. Women played a significant role: Margaret Rock, Mavis Lever and others. Dilly Knox also contributed to the analysis.

Victory in the Atlantic & on D-Day

The Allies read German radio messages almost in real time. U-boat attacks were intercepted, convoys warned. On 6 June 1944, the Normandy landings directly benefited from deciphered troop movements and orders. Historians estimate: Ultra shortened the war by at least one year.

Features

Three layers. Impenetrable security.

001
Enigma Machine

Unicode-capable with up to 50 rotors, 65,536 characters, fully randomized plugboards, reflectors and rotor positions – every message unique.

002
AES-256-GCM

The Enigma ciphertext is encrypted with AES-256 in Galois/Counter Mode. GCM provides encryption and authentication – any tampering is detected and rejected.

003
HKDF-SHA3-256

Fresh keys are derived for every message using HKDF with SHA3-256. Keys rotate after each message (Perfect Forward Secrecy).

004
Argon2id

Password hardening with 64 MB RAM, 3 iterations, 4 threads. A 12-character password means computationally over 1,000 years of brute-force time. GPU and ASIC attacks are structurally neutralized.

005
Split Key

When establishing a connection, each side generates a unique 256-bit random ID. Only when both IDs come together is the shared key created — combined with ECDH (Curve25519). Neither side alone can calculate it.

006
Forward Secrecy²

After the key exchange, the contact ID is irreversibly deleted. Even if all files and source code are later known — past messages remain protected forever.

Quantum Security

Secure against
quantum computers

Grover's algorithm effectively halves the key length. With 768 bits, 384 effective bits remain after quantum attack – 10107 times the age of the universe.

MethodeZeitErgebnis
Brute-Force (10¹⁸/sec)10²¹³ years✔ Secure
Grover's algorithm10¹⁰⁷ years✔ Quantum-resistant
Age of the universe1,4 × 10¹⁰ yearsReference
How it works

Simple to use.
Uncompromisingly secure.

1
Create contact

Create a contact, key file is created automatically.

2
Exchange key file

Exchange securely with partner once.

3
Handshake

Green banner: full security active.

4
Communicate

Encrypt, send, done.

About the program

Your messages belong to you.

RotorCrypt X is free encryption software that protects your communication with a combination of historical Enigma logic and state-of-the-art cryptography. Developed for people who take privacy seriously.

"Secure. Free. Your control."
✔Keys only on your device
✔Fully offline
✔No provider, no access
✔Portable, also USB drive
Download

Download

WINDOWS VERSION (PORTABLE)
RotorCrypt X Portable

The complete desktop application as a portable ZIP file. Simply download, extract and start directly – also from USB drive. No installation required.

⬇ Windows – Download
📦 Download · Extract · Ready to use — no installation needed
⬇ Android – Download
100% compatible with Windows version
FAQ

Frequently asked questions

Can the NSA read my messages?›

No — and for three reasons that together form a wall even state-level actors cannot penetrate.

First: there is nothing to request. No server, no cloud, no database. Whoever issues a court order — there is simply no entity that could hand over any data.

Second: the mathematics do not allow it. The key space contains more combinations than there are atoms in the observable universe — and that is not a metaphor. Even a quantum computer halving the search space via Grover's algorithm faces a computational task that is unsolvable with any physically conceivable means. On top of that: quantum attacks require long-lived keys sitting in memory as a target — those simply do not exist in RotorCrypt X, because they are destroyed immediately after the connection is established.

Third: even with full device access there is nothing to extract. If someone had access to all encrypted files, the device, and the entire source code — past messages would still be gone forever. The key IDs required for decryption were irreversibly deleted the moment the connection was set up. The mathematical path cannot be reconstructed retroactively.

What if my device is stolen?›

Nothing. A thief sees only encrypted garbage — and gets no further. The password is hardened with a technique that brings even GPU clusters to their knees: millions of attempts per second are still useless. After 10 wrong attempts the software automatically wipes all keys to military standard — the device becomes permanently unusable for the attacker.

If the device has not been used for 5 minutes, all keys have already vanished from RAM. No contact name, no plain text, no message is visible on the device — everything is encrypted with no recognizable pattern.

Even if someone had access to all files and the entire source code of the software: past messages cannot be mathematically reconstructed, because the key IDs were irreversibly deleted after the connection was established.

How do I exchange the key with my contact?›

No USB stick needed. Both sides open the app and each generate a one-time random ID. These IDs can be exchanged over any channel — even a messenger or email is sufficient, since the ID alone is useless.

The app derives a shared key from these two IDs that neither side alone knows or can pre-compute. The software then deletes the IDs irreversibly — past messages remain protected even if someone later gains access to the device.

Is the algorithm transparent?›

Fully documented and mathematically verifiable. All security mechanisms are described in the technical documents.

Desktop and Mobile together?›

Yes. Identical key file format (13,600 bytes). PC-encrypted → Android-decrypted – and vice versa.

Shareware vs. Full version – what's the difference?›

The shareware version includes all core functions and is free. However, only 3 rotors are available. For context: during World War II, the original Enigma machine also operated with 3 rotors – and was famously cracked. RotorCrypt X with just 3 rotors is far more secure than the original thanks to modern additional layers (AES-256-GCM, HKDF-SHA3-256) – but for maximum security we strongly recommend the full version with up to 50 rotors. Each additional rotor multiplies the key space and makes decryption without knowing the rotor count virtually impossible.

What is EAR99 and does it apply to me?›

EAR99 is a US export classification for many common commercial goods without special cryptographic restrictions. RotorCrypt X uses only standardized, publicly available algorithms and may fall under this classification. EAR99 is not a global clearance, however — other countries have their own rules. Users are responsible for complying with the applicable national regulations in each case.

Am I allowed to export the software to my country?›

In most countries yes — but not everywhere. Sanctioned or restricted jurisdictions are excluded. The list changes; please check official government sources (e.g. OFAC, EU sanctions lists) or contact us at compliance@bagdadi.de before using the software in regions with an unclear legal situation.

What do I do if I am unsure about the export question?›

Contact a lawyer specialising in export control or write to us at compliance@bagdadi.de. When in doubt: refrain from exporting until the situation is clear. Also check whether the recipient appears on any sanctions or embargo lists (e.g. OFAC, EU lists).

What happens when I switch my Android phone?›

Your messages and settings are not lost — there are two ways, depending on how you proceed.

Setting up a new phone with device transfer: If you use Android's (Google) data transfer when setting up your new phone, the system automatically transfers the app along with its data to the new device. In this case no further action is needed.

Reinstalling via Google Play: If you reinstall the app fresh from the Play Store, all local data — contacts, keys and message histories — will be permanently lost, because RotorCrypt X deliberately creates no cloud backup. Your privacy remains fully protected this way. If you purchased your licence through Google Play, the software automatically recognises your purchase — you do not need to pay again.

Licence key manually: If you purchased your licence key through this website (outside Google Play), you will need to enter it yourself once after reinstalling. Keep your licence key stored safely.