# Encrypt and decrypt files in the Vault

The [Vault](https://securysign.com/#/vault) encrypts files in the browser before uploading them. Encryption can use a key derived through a passkey's pseudorandom function (PRF) extension or a key held in SecurySign's hardware security module (HSM). For an integration in your own application, see the [Encryption API](#/docs/api-encryption).

## What you need

To use the Vault, you'll need:

- your Google account for sign-in;
- a registered passkey;
- a passkey device that supports the WebAuthn PRF extension, if you choose **PRF Hardware**.

## Choose a mode

| Mode | How you encrypt the file | Suitable input |
|---|---|---|
| **PRF Hardware** | Your authenticator derives the file key through the PRF extension when you approve the prompt. | Files you want to decrypt with that authenticator. |
| **AES Secret** | Your browser generates an Advanced Encryption Standard (AES) key, encrypts with AES-256-GCM and wraps the key with your RSA public key. The private RSA key is held in the HSM. | Files encrypted with a separate file key. |
| **Public Key** | Your browser encrypts directly with RSA Optimal Asymmetric Encryption Padding (RSA-OAEP). | Payloads of up to 446 bytes. |

## Encrypt a file

Choose a mode, then add the file in the upload area. **PRF Hardware** obtains the key through an authenticator prompt; the other modes use the account's public encryption key. Once uploaded, the ciphertext appears in the encrypted-document list.

## Decrypt a file

Select **Decrypt** beside a document. **PRF Hardware** requests approval from the same authenticator. With **AES Secret**, the HSM unwraps the account's file key and the browser decrypts the file. With **Public Key**, the HSM decrypts the small payload. The browser then downloads the recovered file.

The delete button removes the stored encrypted copy.
