1Password's own support page says exported vault files are "not encrypted... stored in plaintext" and says to delete them immediately; Bitwarden's export page gives the same warning about its own plain CSV/JSON output. Migrating between password managers almost always still requires that plaintext file, because CSV is the one format nearly every vendor can read. Cybernews' June 2025 discovery of 16 billion exposed credential records — compiled largely from infostealer malware logs pulled off individual devices, per CBS News' reporting — and a March 2025 Krebs on Security report tying a $150 million cryptocurrency theft to offline-cracked vaults from the 2022 LastPass breach both show what is out there looking for a file exactly like this one. Here is what encrypting the export actually closes, and what it honestly doesn't.
A 2019 Manafort court filing, a 2024 Kentucky TikTok lawsuit, and the February 2026 Epstein-files release all failed the same way: a black box was drawn over text that was still sitting there underneath it, recoverable with copy-paste. NSA's own guidance says the fix is deletion, not decoration. Here's why encrypting the whole file is a genuinely different tool that solves neither the redaction problem nor most of it, and what NearSeal honestly can and can't do about a document that needs part of it hidden.
The U.S. Department of Education says nearly 150,000 suspect identities have turned up in FAFSA applications, one district held 10,000 of 26,000 applications for fraud review, and a Nevada college wrote off $7.4 million in fraudulent enrollments — so since fall 2025 every first-time applicant must show a government photo ID in person or on live video. None of that changes what your own financial aid office asks an honest student to email: a tax transcript, W-2s, and often a Social Security card scan. NC State's own instructions tell students to redact the SSN before emailing — but IRS transcripts already mask it to the last four digits, while your W-2 and the school's own worksheet usually don't. Here is which of those files NearSeal can actually protect, and which ones it can't.
Nearly every piece of advice about file encryption has one setting: yes. But encryption is not a property you add to a file, it is a trade — you give up efficient sync, merging, previews, diffs, scanning and per-person access in exchange for bytes nobody can read without the passphrase. That trade is excellent for a file leaving your hands and frequently bad for a file that stays. Here are the three places a file encryptor makes things worse — a sync folder you keep editing in, a team you share with over time, and a Git repository — what the right tool is in each, and what NearSeal honestly cannot do, starting with the fact that a forgotten passphrase cannot be recovered at all.
Japan named the habit of emailing a password-protected ZIP and then emailing the password: PPAP. Its government dropped it from the Cabinet Office on 26 November 2020, IIJ has deleted such attachments on arrival since 26 January 2022, and MUFG Bank is abolishing it in principle from 18 July 2026. But the minister who ended it did not say stop encrypting files — he said put a password on the file and tell the password by a completely different route, such as by phone. Here is the one test that decides whether your second channel is real, what NIST’s 2025 password guidance actually says, and the five limits encryption does not fix — including that a lost passphrase has no recovery at all.
Data-portability rights keep widening — the EU Data Act has applied since 12 September 2025, and South Korea's amended Enforcement Decree took the right to have your own data sent to you from healthcare and telecoms to nearly every sector on 20 August 2026. What comes back is one archive; Google Takeout even offers a 50 GB size option to avoid splitting it. A November 2019 Takeout bug put some users' Google Photos videos into strangers' archives, and in 2018 a GDPR request handed a German man 1,700 Alexa recordings from a stranger's home. EU regulators' own portability guidance told services to recommend encryption measures; almost none do. Here is how to close that window — and what encryption honestly cannot fix.
September is National Preparedness Month, and FEMA's guidance tells you to keep electronic copies of your critical documents in a "password-protected format" on a flash drive or in the cloud. The January 2025 LA fires — 16,251 structures destroyed and 31 lives lost, per LA County — showed why: the moment you need your documents most is the moment they burn. But an emergency kit must be spread out to survive, and spreading plaintext copies of your SSN, passport, and deeds multiplies exposure. Here's how encryption resolves that tension, what "password-protected" should actually mean, and what an encrypted kit honestly can't do.
The Change Healthcare breach reached a final tally of 192.7 million people — more than half the US — and no patient could do anything about it. Meanwhile 65% of Americans now use patient portals, a third of users download their records, and HHS guidance is explicit that HIPAA stops the moment your copy reaches you: providers may even email records unencrypted at your request. Here's what encrypting the copy you actually control changes, and what it honestly can't.
Employment screening firm DISA Global Solutions notified 3.3 million people that an intruder spent ten weeks in its network — and took ten months to tell them; background-check data broker National Public Data went bankrupt after a breach covering roughly 300 million people. Meanwhile the FTC says job-scam reports tripled from 2020 to 2024, with losses jumping from $90 million to $501 million, and fake recruiters ask for the same ID and SSN as real ones. Here's which of those problems encrypting your documents actually addresses — and which one it can't touch.
In 2019, title giant First American exposed roughly 885 million transaction documents — bank statements, SSNs, wire receipts — reachable by changing one digit in a URL; in 2023, ransomware at Fidelity National Financial stole data on 1.3 million customers and froze closings for a week. Meanwhile the FBI counted $2.77 billion in BEC losses in 2024, and CertifID found 26% of home buyers and sellers get suspicious communications during closing. Here's what encrypting the documents you send actually changes, and what it honestly can't.
When Blancco bought 159 used drives on eBay, 42% still held readable data — and every seller claimed they had wiped them. In January 2026, Canada's privacy commissioner found a major retailer reselling returned laptops with 23% still carrying the previous owner's personal information, the same failure its 2011 audit found. Deletion and factory resets leave recoverable remnants; here's why a file that lived its whole life as ciphertext is the exception, and where NearSeal fits.
On dark-web marketplaces surveyed by Comparitech, a digital passport scan sells for an average of $14.71 — and in 2025, bribed support contractors leaked government-ID images for about 69,461 Coinbase customers. In the Marriott breach, 5.25 million unencrypted passport numbers were exposed while 20.3 million encrypted ones survived the same attackers. Here's why the ID copies you control are the easiest gap to close, and where NearSeal fits.
48% of Americans have no instructions for what should happen to their digital accounts and files when they die, per Trust & Will's 2026 Estate Planning Report (5,000 U.S. adults surveyed) — and a 2026 Carnegie Mellon study found most who do plan for it just write passwords on paper. Here's a more durable version: one encrypted file listing your accounts, and a passphrase kept in a completely separate place, using NearSeal's client-side encryption.
In a peer-reviewed 2023 field study (IEEE S&P), technicians snooped on planted personal files in 6 of 16 device drop-offs for repair — and a separate 2025 investigation in Singapore found the same thing in 12 of 40 cases, with one technician copying payslips and passwords to a USB drive. Here's what a repair actually requires access to, and where NearSeal's file-level, passphrase-based encryption fits before you hand a device over.
In 2023, Samsung banned ChatGPT company-wide after employees pasted confidential source code into it three times in 20 days. In 2025, a court ordered OpenAI to preserve even deleted ChatGPT logs, and a sharing feature indexed roughly 4,500 private conversations on Google. Here's what actually happens to a file once it reaches a chatbot, and where NearSeal's client-side encryption does and doesn't help.
In July 2025, WeTransfer's terms briefly granted itself a perpetual, sub-licensable right to reproduce and use uploaded files, including "to improve performance of machine learning models" — before reversing the clause a day after it was noticed. The revised terms still license uploaded content for the company's own use. Here's what encrypting a file before upload actually changes, and what it doesn't.
A 2023 credential-stuffing breach exposed 6.9 million people's 23andMe genetic data, and on July 14, 2026, forty-three state attorneys general secured an $18 million settlement over it. EFF's own advice is to download your raw data and "store it securely" — without saying how. Here's what that should actually mean, and where NearSeal fits.
96% of ransomware attacks in Q3 2025 involved stealing files before locking anything, per BlackFog — and Mandiant/Google Cloud found confirmed data theft in 77% of 2025 intrusions, up from 57% in 2024. A good backup restores access, but it doesn't undo a leak. Here's what actually changes if the files a ransomware group steals were already ciphertext, and where NearSeal's file-level encryption fits.
CBP searched 55,318 electronic devices in FY2025, up 32.4% from FY2023 — and two real 2025/2026 cases show what happens once a device passcode is handed over. Here's the specific gap file-level encryption addresses, and where it doesn't.
The ABA's own ethics rules say a lawyer "should encrypt the transmission" when client information is sensitive enough — and a cited state-bar opinion names the exact scenario: a spouse who still has the password to a shared email account during a divorce. Here's what Model Rule 1.6 actually requires, and why the passphrase has to travel a different way than the file.
A USB drive holding an entire city's resident data survived being lost after a night out; an unencrypted laptop stolen from a car cost a research institute $3.9 million. Drive-level encryption and file-level encryption protect against different things — here's the real difference, three real cases, and where NearSeal's file-level, passphrase-derived encryption fits before anything gets copied to a drive.
GDPR, HIPAA, and most US state laws all give encrypted data some kind of breach-notification exemption — but each attaches its own technical condition, and "we used a password" doesn't automatically satisfy any of them. Here's what the actual statutes and guidance say, quoted directly, and where NearSeal's own encryption fits.
NIST finalized its first post-quantum cryptography standards in 2024 — but those replace RSA and elliptic-curve cryptography, not AES. Here's what Shor's and Grover's algorithms actually threaten, why NIST says AES-256 stays safe for decades, and where NearSeal's passphrase-derived encryption sits in that picture.
Cloud storage's in-transit and at-rest encryption protect against different failures than encrypting the file yourself — and a real, three-year Microsoft Azure exposure shows exactly where that gap opens, and why it matters before you share a tax return or pay stub.
Password-protecting a ZIP feels like it solves the problem of sending a sensitive file, but many "add password" tools still default to a decades-old scheme with a known key-recovery attack — and UK ICO data shows misdirected email is a bigger, more common risk than most people plan for.
A forgotten NearSeal passphrase can't be reset, emailed, or looked up by anyone — including NearSeal. Here's the structural reason why, what actually protects a passphrase-derived key from offline brute force, and what to do about it before you need to.
NearSeal added an opt-in age-encryption.org output format. Here's how a real test — reaching past our own code into the standalone age-encryption library and the official Go age CLI — actually proves it isn't a NearSeal-flavored format wearing an age label.