Documentation · version 0.15.3

Clever PGP Guide

Practical documentation for installation, file encryption, disk containers, and the core rules for safe use.

About Clever PGP

Clever PGP is a local Windows application that protects user-selected data in two ways: it creates a standalone encrypted .cpgp file, or it creates a .cpgv container file that can be mounted as a virtual disk.

ScenarioResultWhen to use it
File protectionA new name.ext.cpgp file beside the originalTransfer, archiving, or storing an individual item
Encrypted diskA single .cpgv file that opens as a drive letterRegular work with folders and many files

The application does not require a cloud account, subscription, or activation server. Cryptographic operations are performed locally.

Installing on Windows

  1. Download the latest version using the Download button on the website.
  2. Run Clever-PGP-Setup-X.Y.Z.exe.
  3. Allow the installer to make system changes. Administrator rights are required for the virtual-disk system components and File Explorer integration.
  4. Complete the setup wizard and launch Clever PGP.
The installer contains the application and required dependencies. A normal user does not need to install Python separately.

SmartScreen

If Windows SmartScreen shows a warning, make sure the installer was downloaded from the official Clever PGP website, then continue setup.

Quick start

Protect one file

  1. Open Clever PGP.
  2. Click Encrypt file.
  3. Select the source file.
  4. Set a password for that file.
  5. Wait for the operation to finish. The original remains unchanged and a .cpgp file is created beside it.

Work with a protected folder or disk

  1. Click Create disk container.
  2. Choose its location and capacity.
  3. Set a password and, when needed, select an algorithm.
  4. Mount the container after it is created.
  5. Work with the new drive letter in File Explorer.
  6. Before moving or powering off the storage device, safely unmount the disk.

Encrypting .cpgp files

When Clever PGP encrypts a file, it does not transform the original in place. The source file remains unchanged and a new encrypted object is created beside it.

What happens internally

  • a new random key is generated for every file;
  • the user's password protects that random key;
  • the content is encrypted as a stream with authentication;
  • modification or tampering should be detected during decryption;
  • the result is published atomically, so an incomplete plaintext file is not presented as successful output.
The original file is not deleted automatically after successful encryption. This reduces the risk of data loss, but the user decides what to do with the plaintext copy.

Decryption

Open the .cpgp file by double-clicking it or choose the Clever PGP action from the context menu. Enter the password for that specific file. If the password is wrong or the file is damaged, Clever PGP shows an error.

Encrypted .cpgv disks

.cpgv is Clever PGP's own container format. After unlocking, it is mounted as a separate virtual disk. You work with it through normal File Explorer operations: create folders, copy files, modify them, and delete them.

Creating a disk

  1. Select Create disk container.
  2. Choose the destination file.
  3. Select the capacity using the slider. The maximum depends on free space on the selected storage device.
  4. Set a disk password.
  5. Select an available backend and algorithm if the interface offers a choice.
  6. Wait for the container to be prepared and mounted.

During creation the interface checks free space. Preparing large containers displays numerical progress.

Opening a disk

Double-click a .cpgv file or select it in Clever PGP. After the correct password is entered, the application authenticates the protected header and selects the appropriate virtual backend. User-file content is not read merely to choose the backend.

Clever PGP does not create an unencrypted temporary folder containing the disk's files. Access is provided through the virtual disk.

Hidden disk

A compatible .cpgv container can contain a hidden volume. The outer and hidden disks use different passwords. The password entered while opening the container determines which volume is mounted.

Protecting the hidden area

If the outer disk is open and you plan to write data to it, you can additionally provide the hidden-disk password. This lets Clever PGP know where the hidden area is located and block writes that could damage it.

Do not treat the existence of a hidden volume as a substitute for backups. Perform container operations only when an independent copy of important data exists.

Managing a mounted disk

For supported formats, the context menu of an active virtual disk shows only operations that are applicable to that disk.

CommandPurpose
OpenOpens the virtual disk in File Explorer.
Disk informationShows capacity, file system, and protection information without revealing the password, key, or biometric data.
Access settingsOpens settings that apply to the selected disk.
Change disk passwordChanges the header password slot without re-encrypting every user file.
Expand diskExpands an unmounted compatible container without re-encrypting existing blocks.
Change algorithmSafely rewrites the container to a temporary image, verifies the result, and only then atomically replaces the original file.
UnmountSynchronizes data and safely stops the virtual disk.

Windows File Explorer integration

After installation, Clever PGP commands are added to the File Explorer context menu. In Windows 11, some commands may appear under Show more options.

  • encrypt a regular file;
  • open and decrypt .cpgp;
  • mount .cpgv;
  • perform operations on an already mounted virtual disk.

The virtual-disk host runs as a separate hidden process. The main Clever PGP window can be closed to the notification area without unmounting an active disk. After restarting, the GUI can discover the running disk through a protected local channel.

Encryption algorithms

AlgorithmUsed forNotes
XChaCha20-Poly1305.cpgp files and disksPortable software mode; does not require CPU AES acceleration.
AES-256-GCMNew regular disks when hardware support is availableCan use hardware AES acceleration on a compatible processor.

Both are authenticated-encryption modes. In addition to confidentiality, they allow Clever PGP to verify the integrity and authenticity of protected blocks.

If you are unsure which option to choose, use the one the application recommends by default for your computer.

Passwords and keys

In Clever PGP it is important to distinguish a password from a data key. A separate random key is generated for every .cpgp file and the password protects that key. For a disk, a random volume key is protected by a password slot in the .cpgv header.

  • file and disk passwords are not stored in the local settings database;
  • the developer has no universal master key that can open user data;
  • changing the password of a compatible disk does not require re-encrypting all files;
  • if the password is lost and no other access method has been configured, recovery of the content is not guaranteed.

Recommendation

Use a long, unique passphrase. Do not keep the only backup of the password beside the container itself.

Biometric access

Clever PGP's architecture treats biometrics as an access-control factor, not as a cryptographic key. A face should not be converted directly into a data-encryption key.

In the current project direction, biometric access is linked to a specific disk only after successful password authentication. This avoids requiring a single global face registration as a mandatory login for the whole application.

Biometric access is linked to the selected drive and complements normal password access.

How data is protected

Clever PGP is designed so that the contents of a protected file or drive open only after correct access. The password is not the file key itself: it helps unlock the separate key that protects the data.

What matters

  • Each file gets a separate random key. One file does not reuse another file’s key.
  • The developer has no universal key. There is no hidden “backup password” that can open every user file or drive.
  • A wrong password does not open the data. Clever PGP verifies access before revealing the contents.
  • Changes to encrypted data are detected. XChaCha20-Poly1305 and AES-256-GCM both hide the contents and let the app verify integrity.
  • Core operations happen on your computer. Encryption and decryption do not require sending the file or password to a cloud service.

Why a strong password matters

Encryption protects the key, but security also depends on the password you choose. Use a long, unique passphrase that is hard to guess. The stronger the password, the harder password-guessing attempts become.

Core principle: without the correct password or key, the data remains encrypted. PGP systems use the same basic confidentiality principle.

Supported features

Clever PGP is designed to protect individual files and encrypted drives in Windows. The items below belong to other types of security software.

  • the Windows operating system is not encrypted;
  • the entire C: system drive is not encrypted;
  • EFI/boot partitions and the boot loader are not encrypted;
  • there is no pre-boot authentication;
  • .cpgv is a proprietary project format and is not compatible with VeraCrypt;
  • older container formats may not be supported by the current version;
  • WinSpd/WinFsp availability depends on the installed system component and Windows configuration.

File formats

ExtensionDescriptionHow to open
.cpgpStandalone encrypted Clever PGP fileWith Clever PGP, by double-clicking, or from the context menu
.cpgvEncrypted virtual-disk containerWith Clever PGP; after entering the password it mounts as a disk

Common problems

The virtual disk does not appear

Check whether the WinSpd/WinFsp system component is installed. If component installation was interrupted, run the Clever PGP installer again using an account with administrator rights.

The command is missing from the Windows 11 context menu

Open Show more options. If the commands are missing there as well, reinstall the integration using the application installer.

Wrong password or damaged file

Check the password and make sure the file was copied completely. If the file is damaged, use a saved copy.

The disk was unexpectedly disconnected

Do not continue writing to a copy of the container whose state is uncertain. Preserve the original .cpgv first, then test using a separate copy.