Encrypt files or folders
- Drag files or folders onto Vern, or choose File → Encrypt Files or Folders….
- Enter the password twice. Apple Encrypted Archive requires at least 31 characters.
- Select Encrypt. Vern creates one
.aea archive beside the selected items.
When several items are selected, Vern keeps them together inside one archive. If an archive with the same name already exists, Vern chooses a numbered name rather than replacing it.
Generate and save a password
Select Generate, Copy & Open Passwords to create a unique 32-character password. Vern fills both fields, copies the password, and opens Apple Passwords.
Save it using the archive’s filename so the two are easy to match later. Vern uses the password only for the current operation. It never saves passwords and cannot recover one you lose.
Open a protected archive
- Double-click the
.aea file in Finder. - Archive Utility asks for the password.
- Enter it to restore the contents beside the archive.
Vern does not need to be installed on the Mac opening the archive. The format and extraction support come from macOS.
If Archive Utility reports an error after restoring a ZIP
Archive Utility can be set to keep expanding anything it extracts. When a Vern archive contains an ordinary ZIP, macOS may successfully restore that ZIP and then immediately try to expand it as a second step.
If the restored ZIP is intentionally not expandable, open Archive Utility, choose Archive Utility → Settings, and turn off Keep expanding if possible. The Vern archive itself was already opened correctly.
Permanent deletion
Original files stay untouched unless you deliberately enable Permanently delete originals after encryption. The first time, Vern explains that the choice is irreversible.
Vern creates the archive, decrypt-verifies every item with the same password, then overwrites regular files where possible and removes the selected originals without using Trash. If verification fails, Vern leaves the originals alone.
Important: APFS, SSD wear leveling, snapshots, cloud copies, and backups may retain other physical copies. No Mac utility can promise forensic erasure on modern storage.
Encryption details
Vern uses Apple Archive’s hkdf_sha256_aesctr_hmac__scrypt password profile with LZFSE compression. In practical terms, that combines scrypt password hardening, HKDF-SHA-256, AES-CTR encryption, and HMAC authentication in Apple’s native encrypted archive format.
The minimum password length is an Apple Encrypted Archive requirement. A generated password is the easiest way to meet it without reusing a password from somewhere else.
Updates and feedback
Choose Vern → Check for Updates… at any time. Vern also performs a quiet version check no more than once per day. It never downloads or installs an update without you.
For help with something not covered here, choose Help → Send Feedback… in Vern.