Encryption and recovery keys
Encryption protects a backup if its drive or remote storage is accessed by someone else. O&O AutoBackup encrypts files individually with authenticated AES-256-GCM and derives the key from the password with Argon2id. It can also hide file and folder names.
The technical terms matter less than the practical promise: without the password or recovery key, copied backup data should not be intelligible. Authentication also lets O&O AutoBackup detect encrypted content that has been altered rather than quietly returning corrupted plaintext.
Encryption is most valuable for a portable drive that could be lost, a shared location, or storage you do not physically control. It also adds responsibility: recovery credentials become part of the backup system.
Enable encryption​
During backup setup:
- Enable Encrypt this backup on the summary page.
- Enter a password of at least eight characters. Longer is more valuable than merely substituting a few symbols.
- Repeat the password exactly.
- Save, print, or securely copy the generated recovery key.
- Confirm that the key has been stored somewhere safe before finishing.
Save or print the recovery key and keep it somewhere separate from the backup destination and the protected PC. A password manager and a secured paper copy are good complements. The key is shown during setup; do not assume it can simply be displayed again later.
Permanent design choice​
Encryption changes how the destination is written. Treat the choice made during setup as permanent for that backup. If you need a different security configuration, create a new backup pair and destination.
Why? Turning encryption on later would leave earlier files readable, while turning it off would not decrypt data already stored. A label claiming that a mixed destination is encrypted would be dangerously misleading.
Only Backup mode supports encryption. A synchronized destination is a working folder whose files must remain directly editable; encrypting them into backup objects would defeat that purpose.
Hide names as well as contents​
Encryption protects file contents, but readable names such as Tax Return 2026.pdf can still reveal sensitive information. Also hide file names and folders stores data under random names and keeps the directory structure in an encrypted index.
With name hiding enabled, manual recovery through Explorer is intentionally impossible. Keep the portable recovery app with the destination and preserve the encrypted index. O&O AutoBackup can rebuild a missing index from stored objects, but some historical organization details cannot be reconstructed perfectly.
Open an encrypted backup​
When browsing or recovering the backup, enter its password. If the password is forgotten, choose the recovery-key option and enter the saved key. Letter case and dashes in the recovery key are not significant.
The unlock dialog can remember access on the current PC so scheduled runs do not prompt each time. Another PC still requires the password or recovery key. See Restore an encrypted backup for the complete recovery procedure.
Important limits​
- O&O Support cannot reconstruct a lost password or recovery key.
- The password should not be stored on the same removable drive as the only backup copy.
- Encryption protects stored backup data, not the unencrypted source files on the PC.
- Losing the destination still loses the backup; encryption does not replace multiple copies.
- Anyone holding the recovery key can read the backup; it is not a harmless receipt.
- Encryption does not compress the files or make the backup smaller.
Without the password or recovery key, an encrypted backup cannot be restored. Verify the password with a test restore and confirm that the recovery sheet's Vault ID matches the backup before trusting it.