Sigil
dev.animeshvarma.sigil
Zapstore _@zapstore.dev Republished from GitHub / F-Droid by the Zapstore main account.
About this app Sigil is an open-source, offline zero-trust encryption utility designed to secure your sensitive data against modern threats. Unlike standard tools that rely on a single algorithm, Sigil offers a flexible "Encryption Profiles" system, allowing you to choose between maximum defense-in-depth or standard compatibility. The application operates entirely offline, performing all cryptographic operations locally on your device with a modern Material 3 interface. New in v0.4.5: Encryption Profiles • Sigil Chain (Default): A pre-configured, multi-layer cascade (XChaCha20 + Serpent + Twofish + AES-256) designed for extreme resistance against cryptanalysis. • Raw Mode: Standard, single-layer encryption (e.g., AES-256-GCM only) for maximum compatibility with external tools and faster processing. • Custom Profiles: Build your own encryption chain! Select from 18 algorithms, reorder layers, and save your custom configuration for repeated use. Core Security Features • Hardware-Backed Vault: Master keys are generated and stored within the Android Trusted Execution Environment (TEE). Your saved encryption passwords never touch the disk in plaintext. • Zero-Knowledge Auth: Support for PINs and Passwords, hashed using Argon2id. Credentials are never stored in a reversible format. • Tamper-Proof Design: Sigil uses an Encrypt-then-MAC architecture. Any data corruption or tampering is detected and rejected before decryption is attempted. • Memory Hygiene: Sensitive data is wiped from RAM immediately after use. A configurable grace period allows for convenient multitasking without compromising security. Privacy & System Hardening • Screen Shield: Utilizes FLAG_SECURE to block screenshots and hide content in the "Recent Apps" overview, protecting against shoulder surfing and spyware. • Clipboard Auto-Wipe: Prevents clipboard managers from retaining your decrypted text. • Truly Offline: No internet permission requested. No analytics, no telemetry, and no cloud backups. Your data never leaves your device. Advanced User Toolkit • Algorithm Registry: Support for 18 ciphers including AES-GCM, XChaCha20-Poly1305, ARIA, Serpent, Twofish, Camellia, and more. • Secure Keystore: Save and manage your encryption keys securely. Includes an Entropy Meter to gauge password strength. • App Lock: Biometric unlock verified by the hardware TEE or a custom high-security PIN. • System Console: View real-time logs of the encryption process, including timing metrics and cryptographic parameters. • Modern UI: Built with Jetpack Compose, featuring Material You dynamic colors and dark/light themes. Technical Specifications • Cryptography Library: Bouncy Castle (v1.83). • Key Derivation: Argon2id (Memory-hard KDF) + SHA-512 pre-hashing to resist GPU brute-force attacks. • Supported Algorithms: AES (GCM/CBC), ChaCha20-Poly1305, XChaCha20-Poly1305, ARIA-256-GCM, Serpent, Twofish, Camellia, SM4, CAST-256, RC6, SEED. • Legacy Support: Blowfish, IDEA, CAST-128, GOST, TEA, XTEA (included for educational purposes). Open Source Transparency The complete source code is available for public audit on GitHub: https://github.com/Animesh-Varma/Sigil For the complete release catalog and planned features, please visit: https://github.com/Animesh-Varma/Sigil/releases For any queries, please contact: sigil@animeshvarma.dev
First release: Jan 30, 2026, 1 total release.
Most recent release: Jan 30, 2026.
Appears in 0 app stacks.
0 sats / 0 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Jan 30, 2026 0.4.5# Sigil v0.4.5 - Encryption Profiles & Authentication Overhaul > [!IMPORTANT] > **PUBLIC BETA NOTICE** > This is a **v0.4.5** development release. While Sigil is fully functional and stable for daily use, it is currently in an active "Beta" phase as it moves toward the v1.0.0 milestone. > > **Compatibility Note:** While we strive for backward compatibility, major security upgrades may occasionally require **breaking changes**. Any release containing breaking changes (e.g., incompatible file formats or vault resets) will be explicitly marked with a **CRITICAL WARNING** at the top of the release notes. This release introduces a comprehensive overhaul of the encryption workflow and authentication mechanisms. It features the new Encryption Profiles system for managed cipher chains, support for alphanumeric passwords, and security hardening across the application lifecycle.
More…
### Cryptography & Profiles * **Implement Encryption Profiles:** Users can now save, manage, and switch between custom cipher chains and standard configurations via JSON persistence. * **Implement Raw Mode:** Added `isRaw` support to bypass Sigil packet headers, enabling standard file compatibility (e.g., generic AES-GCM) alongside the proprietary Sigil Chain. * **New Algorithms:** Implemented **XChaCha20-Poly1305** (manual HChaCha20 derivation) and **ARIA-256-GCM** to address availability issues with Aegis-256 on specific Android artifacts. * **Registry Update:** Updated `AlgorithmRegistry` to support 18 total algorithms. ### Authentication & Security * **Password Support:** Implemented full alphanumeric password support, removing the previous numeric PIN limitation. * **Setup Wizard:** Refactored the lock setup flow into a multi-step wizard (Method Selection -> Input -> Confirmation) to prevent user lockout. * **Lifecycle Hardening:** Implemented stricter `ON_PAUSE` checks to automatically close dialogs, overlays, and sensitive screens when the app is backgrounded. * **Vault Safety:** Added duplicate key detection and overwrite warnings in the secure input components. ### Infrastructure & Documentation * **CI Optimization:** Switched to manual build mode in GitHub Actions and enabled debug artifact generation for easier testing. * **Documentation:** Comprehensive rewrite of README and Fastlane metadata to reflect defense-in-depth strategies and the new profile system. * **Onboarding:** Updated the introductory flow to guide users through the new Profile Selector and distinction between Custom and Standard modes. ### Coming Soon (v0.5.0) [Project Roadmap](https://github.com/users/Animesh-Varma/projects/2/views/3) * **Steganography:** Implementation of Image Steganography and General Steganography tabs. * **Memory Security:** Add a toggle for aggressive memory clearing. * **Security Audit:** Patch side-channel vulnerability attack vectors and re-scan for implementation vulnerabilities. * **UX Overhaul:** Complete overhaul of the onboarding flow. * **Refactoring:** Review data storage hygiene and perform a complexity refactor. > [!NOTE] > **v0.5.0 Release Schedule** > The development cycle for the next milestone will extend longer than the usual monthly cadence. This delay is necessary to accommodate the sheer size of the planned architectural updates (specifically Steganography and Memory Hardening) and due to scheduling conflicts with my academic final examinations. *** ## What's Changed * feat(crypto): implement XChaCha20 & ARIA-256, bump to v0.5.0-dev01 by @Animesh-Varma in https://github.com/Animesh-Varma/Sigil/pull/5 * 📝 Add docstrings to `feature/encryption-profiles` by @coderabbitai[bot] in https://github.com/Animesh-Varma/Sigil/pull/7 * feat(profiles): implement encryption profiles, raw mode & security hardening by @Animesh-Varma in https://github.com/Animesh-Varma/Sigil/pull/6 * feat(auth): implement password support and overhaul lock setup by @Animesh-Varma in https://github.com/Animesh-Varma/Sigil/pull/8 * ci(gha): optimize android workflows, fix codeql & enable artifact generation by @Animesh-Varma in https://github.com/Animesh-Varma/Sigil/pull/9 * chore(release): finalize v0.4.5 docs, update onboarding flow & refresh metadata by @Animesh-Varma in https://github.com/Animesh-Varma/Sigil/pull/11 * chore(release): merge v0.4.5 into master by @Animesh-Varma in https://github.com/Animesh-Varma/Sigil/pull/12 **Full Changelog**: https://github.com/Animesh-Varma/Sigil/compare/v0.4.1...v0.4.5