AES-256-GCM and Argon2id, in plain English

Open the settings of almost any serious encryption tool — Clavis included — and you'll meet two names: AES-256-GCM and Argon2id. They sound like robot serial numbers. They're actually the two jobs behind locking a file with a password: turning your password into a key, and using that key to seal your data. Here's what each one does, no math required.

The problem: a password isn't a key

Encryption needs a key — a long, random-looking value. But humans type passwords, which are short and predictable. If a tool just used your password directly as the key, weak passwords would mean weak encryption. So the first job is turning a password into a proper key. That's Argon2id. The second job is using that key to lock the data. That's AES-256-GCM.

Argon2id: turning a password into a key

Argon2id is a password hashing function. It takes your password and grinds it into a fixed-size key. The clever part is that it's deliberately slow and memory-hungry.

Why would slow be good? Because attackers guess passwords by trying billions of them. If turning one password into a key takes real time and a chunk of memory, the attacker's billions of guesses suddenly cost enormous time and hardware. Argon2id won the international Password Hashing Competition precisely because it resists the custom cracking rigs (GPUs, ASICs) that chew through older methods.

Two more pieces:

  • Salt — a random value mixed in so that two people with the same password still get different keys. It stops attackers from pre-computing answers.
  • The "id" variant — a blend of Argon2's two modes that defends against both memory-inspection and timing attacks. It's the recommended default.
Analogy: a password is a short note; Argon2id is a slow, elaborate machine that turns that note into a one-of-a-kind key. Making a single key is fine for you; making billions is a nightmare for an attacker.

AES-256-GCM: locking the data

AES (Advanced Encryption Standard) is the encryption the world runs on — governments, banks and browsers all use it. Let's unpack the full name:

  • AES — the cipher itself: proven, fast, everywhere.
  • 256 — the key size in bits. A 256-bit key has so many possible values that trying them all is beyond any computer that will ever exist. This is where "brute force is hopeless" actually comes from.
  • GCM (Galois/Counter Mode) — the mode it runs in. GCM doesn't just scramble your data; it also produces an authentication tag that detects tampering.

That last part matters more than people expect. Plain encryption hides your data but can't always tell you if someone flipped a few bytes. GCM is authenticated encryption: on decryption it checks the tag, and if anything was altered — even one byte — it refuses to hand you the file instead of quietly giving you corrupted data.

Analogy: AES-256 is a bank-vault lock; GCM adds a tamper-evident seal across the door. If the seal is broken, you know not to trust what's inside.

Why the two together

They cover different halves of the same job. Argon2id makes sure a human-friendly password becomes a strong key that's painful to guess. AES-256-GCM uses that key to seal your data and prove it wasn't tampered with. Weak key derivation would undermine great encryption; great key derivation with weak encryption would be pointless. You want both — which is why modern tools pair them.

The jargon, decoded

TermIn plain English
Argon2idTurns your password into a strong key, slowly, to defeat guessing
SaltRandom spice so identical passwords don't make identical keys
AESThe world-standard encryption cipher
256-bit keyA key so large that brute force is effectively impossible
GCMA mode that also detects tampering (authenticated encryption)
Authentication tagThe tamper-evident seal checked when you decrypt

What this does not protect against

Strong crypto is not magic. Being honest about the edges:

  • A weak password. Argon2id slows guessing, but "password123" still falls. Use a long, unique password.
  • Malware while a file is open. Once you decrypt and open a file, it's plain data on your PC. Encryption can't protect what's already unlocked in front of you.
  • Forgetting everything. If you lose your password and your recovery key, no one — not even the app's maker — can open your files. That's the whole point.

This is exactly the pairing Clavis uses: your password becomes a key with Argon2id, and your files are sealed with AES-256-GCM, all on your own PC. If you want the specifics, the Security page lays them out.

Try Clavis — free for Windows