GiliSoft File Lock Pro

Encrypt private files and folders, then hide, lock, or restrict access to local drives, USB storage, and shared folders without moving sensitive data to the cloud.

  • Encrypt files and folders into protected GFL or EXE output
  • Hide, lock, or prevent unwanted changes to local data
  • Protect local disks, USB storage, and shared folders
Illustration of protected files and folders on a Windows computer
Windows 11 File Encryption Guide

How to Encrypt Files and Folders on Windows 11

Compare built-in Windows encryption, encrypted archives, private vaults, cloud encryption, and local file protection tools before deciding how to protect documents, photos, videos, and work folders.

Quick Answer: Choose the Right Encryption Method

There is no single Windows 11 method that fits every file. The right choice depends on your Windows edition, whether the protected copy must be portable, and whether you need a folder, a vault, or an entire drive encrypted.

Windows 11 ProUse EFS for certificate-based encryption of files and folders stored on an NTFS drive.
Windows 11 HomeUse an encrypted archive, a private vault, or GiliSoft File Lock Pro because EFS is unavailable.
Whole driveUse BitLocker Drive Encryption on supported Pro editions, or Device Encryption when it is available on a compatible Windows Home device.
Send protected filesCreate an encrypted 7z archive or an EXE encrypted output. Use GFL when the receiving PC has File Lock Pro installed.
Cloud synchronizationConsider Cryptomator or NordLocker when encrypted storage must be available across devices.
Local everyday protectionUse File Lock Pro when you want encryption together with separate hide, lock, and protect tools.
Before encrypting anything: keep a backup, use a strong unique password, and save EFS certificates or BitLocker recovery keys away from the protected computer.

Encryption, Locking, Hiding, and Drive Protection Are Different

Choose the protection type before choosing a tool. Encrypting a file changes its stored contents, while locking or hiding controls how the existing item can be accessed on the current computer.

Encryption

Transforms file content into unreadable data that requires the correct key or password.

Locking

Restricts opening, editing, renaming, deleting, or other access without necessarily changing the stored data.

Hiding

Removes an item from ordinary Explorer or search views but is not automatically the same as cryptographic protection.

Drive protection

Encrypts or controls an entire disk or removable drive instead of creating a protected copy of one file or folder.

Compare Windows 11 File and Folder Encryption Options

The products below do not all solve the same problem. Some encrypt files, some create vaults, and others protect an entire drive. This comparison keeps those differences visible.

MethodWindows HomeLocal useMain approachBest fit
Windows EFSNoYesCertificate-based NTFS encryptionFiles that stay on a supported Windows installation
BitLockerEdition/device dependentYesDrive encryptionLaptops, internal drives, and removable drives
7-Zip / WinRARYesYesEncrypted archiveSending or archiving protected copies
VeraCryptYesYesMounted encrypted containerTechnical users managing a private vault
CryptomatorYesYesEncrypted vaultFiles synchronized through a cloud folder
AxCryptYesYesFile-based encryptionEncrypting and sharing individual files
NordLockerYesCloud focusedEncrypted storageCross-device encrypted cloud access
Folder Lock / Wise Folder Hider ProYesYesLocker, vault, or hide workflowUsers focused on access control and privacy

Method 1: Encrypt Files and Folders with GiliSoft File Lock Pro

1

Create a protected GFL or EXE output

File Lock Pro provides a dedicated File Encryption tool for users who want a local Windows workflow without first building and mounting a virtual disk. It creates a separate encrypted GFL or EXE output; it does not automatically erase or replace the unencrypted source.

  1. Open File Lock Pro and select File Encryption under More Tools.
  2. Click Add Files/Folders and select the private data you want to encrypt.
  3. Choose Encrypt to GFL or Encrypt to EXE.
  4. Select the destination, create the encrypted output, and test it before moving or removing the original copy.
GiliSoft File Lock Pro File Encryption interface for adding files and folders and creating GFL or EXE output
Choose the output carefully: a GFL file is opened through GiliSoft File Lock Pro. An EXE output can be opened as a self-contained encrypted package. Test the protected output and keep a reliable backup before removing any unencrypted source. Hiding File, Locking File, and Protecting File are separate controls for visibility and access.

Method 2: Encrypt a File or Folder with Windows EFS

2

Use account-linked encryption on an NTFS drive

EFS is useful when the data stays on the same PC and should open transparently for the Windows account that encrypted it.

  1. Right-click the file or folder and choose Properties.
  2. Select Advanced on the General tab.
  3. Enable Encrypt contents to secure data, then select OK and Apply.
  4. Choose whether to encrypt only the folder or the folder, subfolders, and files.
  5. Back up the EFS certificate and private key when Windows prompts you.
EFS is not available in Windows 11 Home. If the encryption checkbox is disabled, see how to fix EFS greyed out.

Method 3: Create an Encrypted Archive with 7-Zip or WinRAR

3

Package files into a portable password-protected archive

This route is practical for email, USB delivery, backups, and folders that do not need constant editing.

  1. Select the files or folder and open the archiver's Add to archive command.
  2. Choose the archive format and destination.
  3. Enter a strong password and select an appropriate encryption method such as AES-256 when available.
  4. Enable filename encryption when the format supports it.
  5. Create the archive and test extraction before handling the unencrypted source.
An encrypted archive is a new protected copy. The original files remain unencrypted until you manage them separately.

Method 4: Store Files in a VeraCrypt or Cryptomator Vault

4

Use an encrypted container when many files belong together

Vault-based tools are useful when you want a private workspace rather than separate encrypted copies of every file.

  • VeraCrypt: creates an encrypted container that is mounted like a drive. It offers control but requires container creation and mounting.
  • Cryptomator: creates a vault designed to work well inside cloud-synchronized folders while keeping encryption under the user's control.
  • Keep recovery information separate and dismount or lock the vault when work is finished.

Method 5: Use BitLocker When the Whole Drive Needs Protection

5

Protect data at rest across an internal or removable drive

BitLocker is the better Windows tool when a lost laptop, external disk, or USB drive is the main concern.

  • Open Manage BitLocker and select the target drive.
  • Turn on BitLocker and choose an unlock method.
  • Save the recovery key somewhere separate from the encrypted device.
  • Choose the encryption scope and complete the process before relying on the drive.
BitLocker is drive encryption. It is not a one-click password prompt for one ordinary folder.

Which Method Fits Your Situation?

Shared family computer

Use local encryption or File Lock Pro when private photos and documents must remain separate from other Windows users.

Windows 11 Home

Choose an archive, vault, or third-party file encryption tool because EFS is unavailable.

Client delivery

Choose an encrypted archive or portable encrypted output that the recipient can open through an agreed process.

Cloud folder

Use a vault designed for synchronized storage when files will leave the local PC through a cloud provider.

Lost laptop or drive

Use BitLocker or another full-drive encryption product so data at rest remains protected when the device is offline.

Frequent local work

Use a direct desktop workflow if building, mounting, and dismounting a container would slow down everyday protection.

Windows 11 File and Folder Encryption FAQ

Can Windows 11 Home encrypt a folder with EFS?

No. EFS file encryption is not available in Windows 11 Home. Use an encrypted archive, vault, or local encryption tool instead.

Is BitLocker the same as folder encryption?

No. BitLocker primarily protects a drive. EFS and file encryption applications work at the file or folder level.

Why is Encrypt contents to secure data greyed out?

The Windows edition, file system, policy, or file type may not support EFS. Check those conditions before changing the data.

Does an encrypted archive protect the original folder?

No. It creates a protected archive copy. The source folder remains as it was until you manage it separately.

Should I delete the original after encryption?

First test the encrypted output and keep a reliable backup. Only then decide how the unencrypted source should be handled.

What is the difference between GFL and EXE output?

A GFL file is opened through GiliSoft File Lock Pro. An EXE output is a self-contained encrypted package that can be opened directly with the correct password. Both are separate protected outputs, so test them before handling the original files.

Prefer a direct local encryption workflow?

Use GiliSoft File Lock Pro to create encrypted GFL or EXE output and manage separate hide, lock, protect, monitor, and secure-delete tasks from one Windows application.

Explore File Lock Pro