Shareware

Encryption for the
Next Generation

Three cryptographic layers of protection. No cloud. No server. Fully offline.

RotorCrypt X Demo
▶ WATCH DEMO
2768
Keys
3
Protection Layers
0
Server / Cloud
10
Languages
History

From a Broken Machine to Unbreakable Encryption

The original Enigma machine was cracked by mathematicians during the Second World War. RotorCrypt X eliminates every weakness of that era.

Arthur Scherbius Presents the Enigma

26 letters, rotating rotors, mechanical-electrical encryption. Initially rejected by the military, adopted by the Kriegsmarine from 1926. Scherbius never lived to see its success – he died in 1929 in an accident with his horse-drawn carriage.

Hans-Thilo Schmidt – The First Betrayal

The employee at the German cipher office handed the French intelligence service secret documents: an operating manual and key material. The French passed the information on to British and Polish services.

Marian Rejewski – The Mathematical Breakthrough

At Poland's Biuro Szyfrów (cipher bureau), Rejewski reconstructed the internal logic of the Enigma through mathematical analysis – without ever having seen the machine. Together with Jerzy Różycki and Henryk Zygalski, he laid the foundation for everything that followed.

Cyclometer & Zygalski Sheets

The Poles developed the cyclometer for systematic key determination. Zygalski invented perforated paper sheets that, when overlaid, revealed certain code properties. When the Wehrmacht began changing keys daily from 1936, new methods became necessary.

Bomba kryptologiczna

History's first electromechanical decryption machine. It tested possible keys systematically – a revolutionary approach. But when the Germans introduced additional rotors, the Poles ran up against the limits of their resources.

Knowledge Transfer at Pyry

Shortly before the war began, representatives of Poland, Britain and France met south of Warsaw. Poland handed over machines, methods and all its findings. Without this step, Bletchley Park would have been impossible.

Alan Turing & Gordon Welchman – The British Bombe

As part of the strictly secret Operation Ultra, under the codename Government Code and Cypher School at Bletchley Park, Turing and Welchman developed a considerably more powerful version of the Polish Bomba. The Bombe could not decrypt messages directly – but it drastically narrowed down possible keys. Women played a significant role: Margaret Rock, Mavis Lever and others. Dilly Knox also contributed to the analysis.

Victory in the Atlantic & on D-Day

The Allies read German radio messages almost in real time. U-boat attacks were intercepted, convoys warned. On 6 June 1944, the Normandy landings benefited directly from decrypted troop movements and orders. Historians estimate that Ultra shortened the war by at least a year.

Features

Three Layers. Unbeatable Security.

001
Enigma Machine

Unicode-capable with up to 50 rotors, 65,536 characters and fully randomised plugboards, reflectors and rotor positions – every message is unique.

002
AES-256-GCM

The Enigma ciphertext is encrypted with AES-256 in Galois/Counter Mode. GCM provides both encryption and authentication – any tampering is detected and rejected.

003
HKDF-SHA3-256

Fresh keys are derived for every message via HKDF with SHA3-256. The key rotates after every message (Perfect Forward Secrecy).

004
Argon2id

Password hardening with 64 MB RAM, 3 iterations, 4 threads. A 12-character password translates to over 1,000 years of brute-force time computationally. GPU and ASIC attacks are structurally neutralised.

005
Shared Key

When establishing a connection, each side generates a unique random 256-bit ID. Only when both IDs come together is the shared key created — combined with ECDH (Curve25519). Neither party can compute it alone.

006
Forward Secrecy²

After the key exchange, the contact ID is irretrievably deleted. Even if all files and the source code later become known — past messages remain protected forever.

Quantum Security

Secure Against
Quantum Computers

Grover's algorithm halves the effective key length. With 2⁷⁶⁸ possible keys, RotorCrypt X remains unbreakable even then.

MethodTimeResult
Brute-Force (10¹⁸/sec.)10²¹³ years✔ Secure
Grover-Algorithmus10¹⁰⁷ years✔ Quantum-Safe
Age of the Universe1.4 × 10¹⁰ yearsReference
How It Works

Simple to Use.
Uncompromisingly Secure.

1
Create a Contact

Create a contact, keyfile is generated automatically.

2
Exchange Keyfile

Exchange once, securely, with your contact.

3
Handshake

Green banner: full security active.

4
Communicate

Encrypt, send, done.

About the Program

Your Messages Belong to You.

RotorCrypt X is a free offline encryption software. No account. No registration. No cloud.

✔Keys Only on Your Device
✔Fully Offline
✔No Provider, No Access
✔Portable, Even on a USB Drive
Download

Download
for Free

WINDOWS VERSION (PORTABLE)
RotorCrypt X Portable

The full desktop application as a portable ZIP file. Simply download, extract and launch directly – even from a USB drive. No installation required.

⬇ Windows – Download
📦 Download · Extract · Ready to use — no installation needed
⬇ Android – Download
100% compatible with the Windows version
FAQ

Frequently Asked Questions

Can the NSA Read My Messages?›

No — for three reasons that together form a wall that not even government agencies can break through.

First: there is nothing to request. No server, no cloud, no database. Whoever issues a court order — there simply isn't any party that could hand over data.

Second: the mathematics doesn't allow it. The key space contains more combinations than there are atoms in the observable universe — and that isn't a metaphor. Even a quantum computer that halves the search space via Grover's algorithm faces a computational task that cannot be solved by any physically conceivable means. On top of that: quantum attacks require keys that sit permanently in memory as a target — such keys simply don't exist in RotorCrypt X, because they're destroyed immediately after the connection is established.

Third: even with full device access, there's nothing to gain. Even if someone had access to all encrypted files, the device and the entire source code — past messages would still be gone forever. The key IDs that would be needed for decryption were irrevocably deleted immediately after the connection was established. The mathematical path can no longer be reconstructed retroactively.

What Happens If My Device Is Stolen?›

Nothing. A thief only sees encrypted junk data — and gets no further than that. The password is hardened with a technique that brings even GPU clusters to their knees: millions of attempts per second are still useless. After the 10th incorrect attempt, the software automatically wipes all keys to military standard — the device becomes permanently useless to the attacker.

If the device hasn't been used for 5 minutes, all keys have already vanished from memory anyway. No contact name, no plaintext, no message is visible on the device — everything is encrypted, with no recognisable pattern.

Even if someone had access to all files and the entire source code of the software: past messages can no longer be mathematically reconstructed, because the key IDs were irrevocably deleted after the connection was established.

How Do I Exchange the Key With My Contact?›

No USB drive needed. Both parties open the program and each generate a unique random ID. These IDs are exchanged over any channel — a messaging app or email is enough, since the ID alone is useless.

The program computes a shared key from this, which neither party can know or precompute on its own. The software then irrevocably deletes the IDs — past messages remain protected even if someone later gains access to the device.

Is the Algorithm Transparent?›

Fully documented and mathematically verifiable. All security mechanisms are described in the technical documentation.

Desktop and Mobile Together?›

Yes. Identical keyfile format (13,600 bytes). Encrypted on PC → decrypted on Android – and vice versa.

Shareware vs Full Version – What's the Difference?›

The shareware version includes all core functions and is free. However, only 3 rotors are available. For context: during the Second World War, the original Enigma machine also worked with 3 rotors – and, as is well known, was cracked. RotorCrypt X with just 3 rotors is significantly more secure than the original thanks to the modern additional layers (AES-256-GCM, HKDF-SHA3-256) – but for maximum security we strongly recommend the full version with up to 50 rotors. Every additional rotor multiplies the key space and makes decryption without knowledge of the rotor count nearly impossible.

What Is EAR99 and Does It Apply to Me?›

EAR99 is a US export classification for many common commercial goods without special cryptographic restrictions. RotorCrypt X uses exclusively standardised, publicly available algorithms and may fall under this classification. However, EAR99 is not a worldwide clearance – other countries have their own rules. Users are themselves responsible for complying with the applicable national regulations.

Am I Allowed to Export the Software to My Country?›

In most countries yes – but not everywhere. Sanctioned or restricted jurisdictions are excluded. The list changes; check official government sources (e.g. OFAC, EU sanctions lists) or contact us at compliance@bagdadi.de before using the software in regions with an unclear legal status.

What Do I Do If I'm Unsure About the Export Question?›

Contact a lawyer specialising in export control or write to us at compliance@bagdadi.de. When in doubt: refrain from exporting until clarity is established. Also check whether the recipient is on sanctions or embargo lists (e.g. OFAC, EU lists).

What Happens If I Switch My Android Phone?›

Your messages and settings won't be lost — there are two ways to go about this, depending on how you proceed.

Setting up a new phone with device transfer: If you use Android's (Google's) data transfer when setting up your new phone, the system automatically transfers the app along with its data to the new device. In this case, no further action is needed.

Reinstalling via Google Play: If you reinstall the app fresh from the Play Store, all local data — contacts, keys and message history — is irretrievably lost, as RotorCrypt X deliberately does not create a cloud backup. This keeps your privacy fully protected. If you purchased your licence via Google Play, the software automatically recognises your purchase — you don't need to pay again.

Manual licence key: If you purchased your licence key via this website (outside Google Play), you'll need to re-enter it yourself once after reinstalling. Be sure to keep your licence key stored securely.

de Deutsch en English fr Français es Español tr Türkçe ja 日本語 zh 中文 ar العربية ru Русский pt Português pk اردو id Bahasa Indonesia it Italiano kr 한국어 my Bahasa Melayu pl Polski se Svenska sg English (Singapore) gr Ελληνικά in हिन्दी