Three cryptographic layers of protection. No cloud. No server. Fully offline.
The original Enigma machine was cracked by mathematicians during the Second World War. RotorCrypt X eliminates every weakness of that era.
26 letters, rotating rotors, mechanical-electrical encryption. Initially rejected by the military, adopted by the Kriegsmarine from 1926. Scherbius never lived to see its success – he died in 1929 in an accident with his horse-drawn carriage.
The employee at the German cipher office handed the French intelligence service secret documents: an operating manual and key material. The French passed the information on to British and Polish services.
At Poland's Biuro Szyfrów (cipher bureau), Rejewski reconstructed the internal logic of the Enigma through mathematical analysis – without ever having seen the machine. Together with Jerzy Różycki and Henryk Zygalski, he laid the foundation for everything that followed.
The Poles developed the cyclometer for systematic key determination. Zygalski invented perforated paper sheets that, when overlaid, revealed certain code properties. When the Wehrmacht began changing keys daily from 1936, new methods became necessary.
History's first electromechanical decryption machine. It tested possible keys systematically – a revolutionary approach. But when the Germans introduced additional rotors, the Poles ran up against the limits of their resources.
Shortly before the war began, representatives of Poland, Britain and France met south of Warsaw. Poland handed over machines, methods and all its findings. Without this step, Bletchley Park would have been impossible.
As part of the strictly secret Operation Ultra, under the codename Government Code and Cypher School at Bletchley Park, Turing and Welchman developed a considerably more powerful version of the Polish Bomba. The Bombe could not decrypt messages directly – but it drastically narrowed down possible keys. Women played a significant role: Margaret Rock, Mavis Lever and others. Dilly Knox also contributed to the analysis.
The Allies read German radio messages almost in real time. U-boat attacks were intercepted, convoys warned. On 6 June 1944, the Normandy landings benefited directly from decrypted troop movements and orders. Historians estimate that Ultra shortened the war by at least a year.
Unicode-capable with up to 50 rotors, 65,536 characters and fully randomised plugboards, reflectors and rotor positions – every message is unique.
The Enigma ciphertext is encrypted with AES-256 in Galois/Counter Mode. GCM provides both encryption and authentication – any tampering is detected and rejected.
Fresh keys are derived for every message via HKDF with SHA3-256. The key rotates after every message (Perfect Forward Secrecy).
Password hardening with 64 MB RAM, 3 iterations, 4 threads. A 12-character password translates to over 1,000 years of brute-force time computationally. GPU and ASIC attacks are structurally neutralised.
When establishing a connection, each side generates a unique random 256-bit ID. Only when both IDs come together is the shared key created — combined with ECDH (Curve25519). Neither party can compute it alone.
After the key exchange, the contact ID is irretrievably deleted. Even if all files and the source code later become known — past messages remain protected forever.
Grover's algorithm halves the effective key length. With 2⁷⁶⁸ possible keys, RotorCrypt X remains unbreakable even then.
| Method | Time | Result |
|---|---|---|
| Brute-Force (10¹⁸/sec.) | 10²¹³ years | ✔ Secure |
| Grover-Algorithmus | 10¹⁰⁷ years | ✔ Quantum-Safe |
| Age of the Universe | 1.4 × 10¹⁰ years | Reference |
Create a contact, keyfile is generated automatically.
Exchange once, securely, with your contact.
Green banner: full security active.
Encrypt, send, done.
RotorCrypt X is a free offline encryption software. No account. No registration. No cloud.
The full desktop application as a portable ZIP file. Simply download, extract and launch directly – even from a USB drive. No installation required.
⬇ Windows – DownloadNo — for three reasons that together form a wall that not even government agencies can break through.
First: there is nothing to request. No server, no cloud, no database. Whoever issues a court order — there simply isn't any party that could hand over data.
Second: the mathematics doesn't allow it. The key space contains more combinations than there are atoms in the observable universe — and that isn't a metaphor. Even a quantum computer that halves the search space via Grover's algorithm faces a computational task that cannot be solved by any physically conceivable means. On top of that: quantum attacks require keys that sit permanently in memory as a target — such keys simply don't exist in RotorCrypt X, because they're destroyed immediately after the connection is established.
Third: even with full device access, there's nothing to gain. Even if someone had access to all encrypted files, the device and the entire source code — past messages would still be gone forever. The key IDs that would be needed for decryption were irrevocably deleted immediately after the connection was established. The mathematical path can no longer be reconstructed retroactively.
Nothing. A thief only sees encrypted junk data — and gets no further than that. The password is hardened with a technique that brings even GPU clusters to their knees: millions of attempts per second are still useless. After the 10th incorrect attempt, the software automatically wipes all keys to military standard — the device becomes permanently useless to the attacker.
If the device hasn't been used for 5 minutes, all keys have already vanished from memory anyway. No contact name, no plaintext, no message is visible on the device — everything is encrypted, with no recognisable pattern.
Even if someone had access to all files and the entire source code of the software: past messages can no longer be mathematically reconstructed, because the key IDs were irrevocably deleted after the connection was established.
No USB drive needed. Both parties open the program and each generate a unique random ID. These IDs are exchanged over any channel — a messaging app or email is enough, since the ID alone is useless.
The program computes a shared key from this, which neither party can know or precompute on its own. The software then irrevocably deletes the IDs — past messages remain protected even if someone later gains access to the device.
Fully documented and mathematically verifiable. All security mechanisms are described in the technical documentation.
Yes. Identical keyfile format (13,600 bytes). Encrypted on PC → decrypted on Android – and vice versa.
The shareware version includes all core functions and is free. However, only 3 rotors are available. For context: during the Second World War, the original Enigma machine also worked with 3 rotors – and, as is well known, was cracked. RotorCrypt X with just 3 rotors is significantly more secure than the original thanks to the modern additional layers (AES-256-GCM, HKDF-SHA3-256) – but for maximum security we strongly recommend the full version with up to 50 rotors. Every additional rotor multiplies the key space and makes decryption without knowledge of the rotor count nearly impossible.
EAR99 is a US export classification for many common commercial goods without special cryptographic restrictions. RotorCrypt X uses exclusively standardised, publicly available algorithms and may fall under this classification. However, EAR99 is not a worldwide clearance – other countries have their own rules. Users are themselves responsible for complying with the applicable national regulations.
In most countries yes – but not everywhere. Sanctioned or restricted jurisdictions are excluded. The list changes; check official government sources (e.g. OFAC, EU sanctions lists) or contact us at compliance@bagdadi.de before using the software in regions with an unclear legal status.
Contact a lawyer specialising in export control or write to us at compliance@bagdadi.de. When in doubt: refrain from exporting until clarity is established. Also check whether the recipient is on sanctions or embargo lists (e.g. OFAC, EU lists).
Your messages and settings won't be lost — there are two ways to go about this, depending on how you proceed.
Setting up a new phone with device transfer: If you use Android's (Google's) data transfer when setting up your new phone, the system automatically transfers the app along with its data to the new device. In this case, no further action is needed.
Reinstalling via Google Play: If you reinstall the app fresh from the Play Store, all local data — contacts, keys and message history — is irretrievably lost, as RotorCrypt X deliberately does not create a cloud backup. This keeps your privacy fully protected. If you purchased your licence via Google Play, the software automatically recognises your purchase — you don't need to pay again.
Manual licence key: If you purchased your licence key via this website (outside Google Play), you'll need to re-enter it yourself once after reinstalling. Be sure to keep your licence key stored securely.
We have created this website to the best of our knowledge and with the greatest care. However, we cannot guarantee the accuracy, completeness or currency of our content. As the service provider of this website, we are responsible for our own content on these pages in accordance with general law, pursuant to Section 7(1) of the German Telemedia Act (TMG). Under Sections 8 to 10 TMG, as a service provider we are not obliged to monitor transmitted or stored third-party information, nor to investigate circumstances that indicate unlawful or improper activity. Any obligations to remove or block the use of information under general law remain unaffected.
Liability in this respect is only possible from the point at which we become aware of a specific infringement. If we become aware of any such infringements, we will remove the relevant content immediately and act in accordance with the law.
Our website may contain links to external third-party websites. We have no influence over the content of these directly or indirectly linked websites. We therefore cannot accept any responsibility for the accuracy of content on external links. Responsibility for the content of external links lies with the respective provider or operator of the site.
The external links were checked for possible legal violations at the time they were set and were free of unlawful content at that time. Continuous monitoring of the content of external links without concrete evidence of an infringement is not reasonable. If we become aware of any infringements, we will remove the relevant external links immediately.
This disclaimer also applies within the bagdadi.de website itself. For illegal, incorrect or incomplete content, and in particular for damages arising from the use or non-use of information presented in this way, only the service provider of the page being referred to is liable, not the party that merely links to that particular publication.
The content and works published on our website are subject to German copyright law. Reproduction, editing, distribution and any kind of use outside the limits of copyright law require the prior written consent of the respective author. Downloads and copies of this site are only permitted for private, non-commercial use. Where the content on our website was not created by us, third-party copyrights are respected. If you become aware of a copyright infringement, please notify us accordingly. If we become aware of any infringements, we will remove such content immediately.
Terms of Use for the Encryption Software RotorCrypt X
This software is used to encrypt files and data. By using the software, you agree to these terms of use.
— Use of the software is entirely at your own risk.
— The developer does not guarantee that the software will function without errors or be available at all times.
— No assurance is given regarding the security, integrity or permanent functionality of the software.
The user is solely responsible for:
— Storing encrypted files securely, regardless of whether they are kept on a USB drive, an external hard disk or a local PC.
— Note: it is expressly recommended not to store encrypted files in cloud services, as third parties (e.g. service providers or government agencies acting within legal authority) could in principle gain access, or such access possibilities may exist.
— Creating backups to avoid data loss.
— Keeping passwords, keys or recovery information stored securely.
— Checking whether use of the software is legally permitted in the relevant country.
The developer accepts no liability whatsoever, particularly not for:
— Data loss, data corruption or unauthorised access
— Damage caused by improper use
— Damage caused by security vulnerabilities, software errors or incompatibilities
— Indirect damages, consequential damages or loss of profit
Any liability — regardless of legal grounds — is excluded to the extent permitted by law.
— There is no guarantee that the encryption is unbreakable under all circumstances.
— New technologies, attacks or errors may compromise security.
— The developer may modify, extend or discontinue the software at any time.
— There is no entitlement to updates, support or further development.
The software must not be used for:
— Unlawful activities
— Concealing or hiding illegal content
— Actions that violate applicable data protection or security laws
The software processes exclusively the data that the user encrypts themselves. No personal data is transmitted to the developer unless expressly stated otherwise.
Should individual provisions of these terms of use be invalid, the validity of the remaining provisions shall remain unaffected.
The law of the country in which the developer is based shall apply, unless mandatory statutory provisions dictate otherwise.
Information in Accordance with Section 5 TMG
Tarek Bagdadi
Am Funkturm 10
44309 Dortmund
Germany
Contact
Phone: 0231 / 13471548
E-Mail: [email protected]
RotorCrypt X is a self-developed encryption software offered as shareware. Both the free version (shareware) and the full version (paid purchase via authorised sellers) are available. No VAT identification number applies.
Disclaimer, copyright and privacy notices: see the respective tabs.
Last updated: May 2026
RotorCrypt X is a research and privacy tool. The software uses standardised cryptographic algorithms (AES-256, SHA3-256, HKDF). The distribution, transfer or export of this software may be subject to national and international export controls. Users are responsible for complying with the applicable laws.
To the best of our knowledge, RotorCrypt X uses exclusively standardised, publicly available algorithms and may fall under the EAR99 classification. However, EAR99 does not release users from the obligation to check and comply with national or international export and sanctions regulations.
The user confirms that they are familiar with and will comply with the applicable national and international export, sanctions and foreign trade regulations. The user undertakes not to supply the software, directly or indirectly, to persons, organisations or countries subject to sanctions or embargoes under applicable law.
The provider states that the software uses standardised, publicly available cryptographic algorithms and, to the best of its knowledge, may fall under the EAR99 classification. This statement does not replace the user's obligation to carry out their own checks.
The user undertakes to carry out an appropriate end-user and end-use check prior to delivery or provision of the software. At the provider's request, the user must provide written evidence of identity, location, intended use and any relevant approvals.
The user shall inform the provider immediately if they become aware that an export, transfer or use of the software could violate applicable export or sanctions regulations.
The user shall indemnify the provider against all claims, damages, costs and expenses (including reasonable legal fees) arising from a breach of the above obligations.
If the user violates this clause, the provider is entitled to immediately discontinue the provision of the software and terminate any existing licences.
The software must not be used for unlawful purposes, to circumvent sanctions, or to support terrorist or criminal activities.
For questions regarding export compliance or use in your jurisdiction, please contact us:
— E-Mail: compliance@bagdadi.de
— Subject: Compliance Enquiry – RotorCryptX
— Required information: organisation name; country of registration; intended use; contact person; project description if applicable.
We typically respond within 5 business days. This contact option does not replace legal advice.
Last updated: March 2026
These Terms and Conditions apply to all purchases of the full version of RotorCrypt X. The contracting party is the provider of this website (see Company Info), hereinafter referred to as the “Provider”.
Payment processing is carried out via an authorised payment service provider, which acts as the merchant of record and concludes the purchase agreement with the buyer as part of the technical processing.
The subject of the purchase is a non-exclusive, non-transferable single-seat licence for use of the full version of RotorCrypt X.
The shareware version (3 rotors) is available free of charge. Purchase unlocks the full version (up to 50 rotors).
The licence entitles installation and use on one device. Parallel use on multiple devices at the same time is not permitted.
Not permitted: resale, sub-licensing, decompilation, reverse engineering, or commercial use without a separate agreement.
The price displayed at the time of ordering is binding. All prices include the statutory VAT applicable to the buyer's respective country.
Payment is made via the payment methods offered. Billing occurs immediately upon ordering.
The licence key is delivered by email after successful payment.
Consumers are generally entitled to a 14-day right of withdrawal.
For digital content, the right of withdrawal expires early as soon as performance of the contract has begun and the consumer has expressly agreed to lose their right of withdrawal once the licence key has been provided (Section 356(5) of the German Civil Code, BGB).
If the right of withdrawal has not yet expired, withdrawal may be declared by email to [email protected] If successful, the purchase price will be refunded within 14 days and the licence key will be deactivated.
It is warranted that the software substantially conforms to the product description at the time of delivery.
Defects are remedied by providing an update or a corrected version. If subsequent performance fails, the statutory rights (price reduction, withdrawal) apply.
The warranty period is two years from delivery of the licence key.
Liability is unlimited for damages resulting from injury to life, body or health, as well as for intentional or grossly negligent conduct.
In all other respects, liability is limited to foreseeable damage typical of the contract.
RotorCrypt X is a tool for local data encryption. No liability is accepted for the loss of keyfiles or encrypted data. It is the user's responsibility to make backup copies of keyfiles.
The buyer is solely responsible for complying with the applicable export and import regulations of their country. Encryption software is subject to special restrictions in some countries.
During the purchase process, personal data (name, email, payment details) is processed exclusively for contract fulfilment. The separate privacy policy of this website applies. Data required for payment processing is passed on to the payment service provider. For questions: [email protected]
The law of the Federal Republic of Germany applies, excluding the United Nations Convention on Contracts for the International Sale of Goods (CISG).
The place of jurisdiction for merchants and persons without a general place of jurisdiction in Germany is Dortmund.
Should individual provisions of these Terms and Conditions be invalid, the validity of the remaining provisions shall remain unaffected.