Encrypted Storage Review
NordLocker is end-to-end encrypted cloud storage from Nord Security — the team behind NordVPN and NordPass. It positions against Tresorit, Sync.com, and Proton Drive in the privacy-first storage category, and against mainstream Dropbox/Google Drive for users who care that their cloud provider can't read their files.
Overview
NordLocker is a zero-knowledge encrypted file storage service. You upload files, they get encrypted on your device before they leave it, and Nord stores the encrypted blobs on their cloud infrastructure. Nord can't read your files. Government subpoenas to Nord can't read your files. Even Nord's own engineers can't read your files. That's the entire point.
This is meaningfully different from Dropbox, Google Drive, or OneDrive — those services CAN read your files (and do, for features like preview generation, search indexing, content scanning, and government compliance). NordLocker trades some convenience features (no in-cloud preview, no server-side search) for a fundamentally different security model: your files are mathematically inaccessible to anyone without your key, including Nord itself.
The category — privacy-first encrypted cloud storage — has been dominated by Tresorit (enterprise-focused, expensive), Sync.com (consumer-focused, very good), and Proton Drive (newer, growing fast). NordLocker entered the space in 2019 and has gradually expanded from a desktop-only encryption app into a full cross-platform sync-and-share service.
For users already in the Nord ecosystem — paying for NordVPN, NordPass, or NordProtect — NordLocker completes the four-pillar Nord security stack: network privacy + credential security + identity monitoring + file privacy. Single account, single billing, single brand-trust relationship across all four.
Why end-to-end encrypted storage matters: "We encrypt your files" sounds reassuring but means almost nothing on its own. The real question is who holds the encryption keys. Dropbox and Google Drive encrypt your files but they hold the keys — meaning they can decrypt and read your data, and so can anyone they're legally compelled to share access with. NordLocker (like Tresorit, Sync.com, Proton Drive) uses zero-knowledge architecture: keys are derived from your password and stored only on your devices. Nord literally cannot decrypt your data even if asked.
Security Architecture
Files are encrypted on your device using XChaCha20 — a modern stream cipher that's faster than AES on most hardware and is the same algorithm used by WireGuard and the Signal protocol. The encrypted file is what gets uploaded to Nord's servers; the unencrypted version never leaves your device.
Your encryption keys are derived from your master password using Argon2 (the modern password-hashing standard, more resistant to GPU/ASIC cracking than older PBKDF2). The keys never reach Nord's servers. If you forget your master password, even Nord cannot recover your data — that's by design.
When you share a file with another NordLocker user, Ed25519 elliptic-curve signatures verify that the file came from you and hasn't been tampered with. The recipient's public key is used to encrypt the file specifically for them — Nord can't intercept and read shared files either.
NordLocker has been audited by independent security researchers — verify the most recent audit report on Nord's official site before subscribing if security verification matters to you. Independent audits are the difference between "trust us" and "verify us" for any encryption product.
Core Features
Native apps for Windows, macOS, iOS, and Android. Web access available for situations where you can't install a client. Files sync across all your devices automatically once uploaded — same model as Dropbox, just with the encryption layer underneath.
Share encrypted files with other NordLocker users via end-to-end encrypted links. Generate sharing links with optional passwords for non-NordLocker recipients. Set expiration dates so links auto-revoke. This is the everyday productivity use case — sending a sensitive document to a colleague without exposing it to the recipient's email provider or any intermediary.
Keep historical versions of files so accidental edits, ransomware, or local corruption can be rolled back. Version retention varies by plan — verify on the official site for the specific period covered by each tier.
NordLocker supports both cloud-synced "lockers" and local-only encrypted folders. Local-only mode is useful for files too sensitive to upload anywhere — they're encrypted on disk but never sent to Nord's servers. Useful for legal documents, financial records, or compliance-bound data.
Daily use is the same as Dropbox — drag files into a NordLocker folder, they upload, encrypted, in the background. The encryption layer is invisible during normal use; it only becomes visible if you ever need to recover a file or share it externally.
Encrypt any file type — documents, photos, videos, application data, software builds, raw camera files. The encryption is at the file level, agnostic to content. Some encrypted-storage competitors restrict large files or specific types; NordLocker doesn't.
Your cloud provider shouldn't be able to read your files. NordLocker fixes that with zero-knowledge encryption — and starts with a free tier so you can test it.
Try NordLocker FreeNord Ecosystem Fit
NordLocker is the fourth pillar of Nord Security's consumer privacy stack. Each product addresses a different layer of personal digital security:
Encrypts your internet connection so your ISP, employer, or public Wi-Fi can't see what you do online. Layer addressed: data in transit.
Encrypted password vault that prevents the most common breach vector. Layer addressed: data at rest (credentials specifically). Read NordPass review →
Detects when your personal information leaks despite the other layers, helps you recover. Layer addressed: data already-compromised. Read NordProtect review →
Encrypts the actual files you store and share, including sensitive documents that would otherwise sit in plain-text-readable form on Dropbox or Google Drive. Layer addressed: data at rest (files).
For a household running all four, the security model is comprehensive: traffic encrypted in transit (NordVPN), credentials protected at rest (NordPass), identity monitored for leaks (NordProtect), and files protected at rest with zero-knowledge encryption (NordLocker). One account, one dashboard, one bill.
Competitive Position
The privacy-first encrypted storage category has four meaningful players. Each has different strengths:
Tresorit is the enterprise-focused leader — Swiss-based, GDPR/HIPAA-compliant out of the box, expensive ($12-25+/user/month). NordLocker is significantly more affordable for individuals and small teams. Tresorit wins for enterprises with strict compliance needs; NordLocker wins for everyone else who wants similar security at consumer pricing.
Sync.com (Canadian) is the closest direct competitor — also zero-knowledge, also reasonably priced, also targets individuals and small teams. Sync.com has slightly better collaborative editing features; NordLocker has the Nord brand and ecosystem integration. If you're already paying Nord for VPN or passwords, NordLocker is the natural pick. If you're starting fresh and only need encrypted storage, both are credible.
Proton Drive (Swiss) is part of the Proton ecosystem (ProtonMail, Proton VPN, Proton Pass). Direct ecosystem analog to NordLocker within the Nord ecosystem. Proton has stronger journalism/activist street cred; Nord has stronger consumer mainstream brand reach. If you're already in Proton's stack, stay there. If you're in Nord's, NordLocker.
Different category entirely. Dropbox/Google can read your files; NordLocker can't. Dropbox has better collaborative editing, deeper integrations, and bigger storage tiers at the high end. NordLocker provides a fundamentally different security model that's worth the trade-off if your stored files include anything sensitive.
Use Cases
End-to-end encrypted storage isn't necessary for everyone. Here's where it genuinely earns its place over Dropbox-style storage:
Years of tax returns, brokerage statements, and bank records contain enough personally-identifying information for full identity theft. Storing them on Dropbox is putting your financial fingerprint in a place a breach or insider can read. NordLocker keeps them mathematically inaccessible to anyone without your key.
HIPAA covers what providers do with your records, not what YOU do once you have copies. Most personal medical records sit in unencrypted email or cloud folders. Encrypted storage is the right layer.
Wills, trusts, divorce decrees, contracts, NDAs. Anything where unauthorized access could create real legal or financial exposure. Encrypted storage is appropriate; mainstream cloud storage isn't.
Source code, design files, manuscripts, research data, business plans, prototypes. If competitors getting access would harm you, NordLocker is the right tier.
This one is debated. Mainstream cloud is fine if you're comfortable with the provider scanning images. NordLocker is better if you want privacy from your provider — particularly relevant after various cloud-storage providers have rolled out automated content-scanning features.
The honest test: would you be embarrassed, harmed, or legally exposed if a copy of this file appeared in a data breach? If yes, it belongs in encrypted storage. If no, mainstream cloud is fine.
Pricing
NordLocker uses Nord Security's standard pricing model: monthly billing for flexibility, annual or multi-year commitments for substantial discounts. Like other Nord products, the published "monthly" price is rarely what you'll pay if you commit to annual billing — promotional discounts of 60-70% off for new annual subscribers are typical.
NordLocker also offers a free tier with limited storage — useful for evaluating the product, encrypting a small set of sensitive documents, or as a long-term lightweight option for users who only need encryption for a handful of files. Verify the current free-tier storage limit on the official site.
Bundle considerations: If you already pay Nord for NordVPN, NordPass, or NordProtect, check whether bundle pricing applies — multi-product Nord subscribers often get better per-product pricing than buying each separately. The Nord Plus / Nord Complete bundle structures occasionally shift; verify current bundle options at signup.
Assessment
Recommendation
Tax returns, medical records, legal documents, financial statements, IP. If you currently have these on Dropbox, Google Drive, or OneDrive, you have a privacy gap. NordLocker closes it without sacrificing the basic sync-and-share workflow.
NordVPN, NordPass, or NordProtect customers get the consolidated billing, single-sign-on, and unified support advantage. Adding NordLocker completes a four-product security stack with one vendor relationship.
Client work that includes sensitive data — financial records, medical files, legal documents — has a real obligation around storage security. End-to-end encryption is the right baseline. Cheaper than Tresorit's enterprise tiers.
If you've already taken steps like using a VPN, password manager, or encrypted messaging — encrypted file storage is the natural next layer. Many people miss it because mainstream cloud storage feels "good enough" until it isn't.
Who should look elsewhere: If you need deep collaborative editing (real-time document editing with multiple users), Dropbox or Google Drive remain stronger. If you have enterprise compliance needs (SOC 2, HIPAA BAA, GDPR processing agreements), Tresorit has the deeper compliance certifications. For pure consumer privacy storage, NordLocker is competitive with anything except the largest enterprise solutions.
Common Questions
Yes. The encryption keys are derived from your master password using Argon2 and never leave your devices. Nord's servers store only the encrypted blobs and the metadata they need to operate the service (file IDs, sync timestamps, etc.). Independent security audits have verified this architecture — check Nord's official site for the most recent audit report.
Your data becomes unrecoverable. This is by design — if Nord could recover your data, the zero-knowledge promise would be a lie. NordLocker provides a recovery key during setup; print it and store it somewhere physical (a safe deposit box, fireproof home safe). If you lose both the master password and the recovery key, the encrypted data is mathematically inaccessible to everyone, including Nord.
Both are zero-knowledge encrypted cloud storage from privacy-first vendors. Proton Drive is part of the Proton ecosystem (ProtonMail, Proton VPN, Proton Pass) — pick it if you're committed to Proton's broader stack. NordLocker is part of the Nord ecosystem (NordVPN, NordPass, NordProtect) — pick it if you're in Nord's stack. The underlying encryption quality is comparable; the choice is mostly about which ecosystem you're consolidating around.
Yes — generate a sharing link with an optional password. The recipient downloads through their browser, decrypting the file with the password you provide separately (best practice: send the link in one channel, the password in another). For ongoing collaboration, both parties having NordLocker accounts is smoother than one-off external shares.
NordVPN encrypts traffic in transit. NordPass encrypts your credentials at rest. Neither protects the actual files you store on cloud services like Dropbox, Google Drive, or OneDrive — those providers can still read your files. NordLocker addresses that specific gap. The three Nord products are complementary, not redundant.
Final Verdict
NordLocker delivers what end-to-end encrypted cloud storage should deliver: modern crypto, zero-knowledge architecture, cross-platform native apps, secure sharing, and a free tier for evaluation. It's not the most feature-rich storage product on the market — Dropbox and Google Drive still beat it on collaborative features, and Tresorit beats it on enterprise compliance depth. But for the core promise of "store sensitive files in the cloud without your provider being able to read them," NordLocker is competitive with anything in the category.
The strongest case for NordLocker isn't standalone — it's ecosystem. If you're already paying Nord for VPN service or password management, NordLocker completes a four-product privacy stack from one vendor. The administrative simplification (one account, one bill, one support team) is meaningful real value over a multi-year subscription period.
Our 8.7/10 rating reflects this: strong product, modern crypto, smart positioning, slight gap behind Tresorit on enterprise features and behind Dropbox on collaboration features. For most consumer and freelancer use cases — which is most use cases — NordLocker is the right pick.
End-to-end encryption, zero-knowledge architecture, cross-platform sync — and a free tier to test before you commit. Built by the team behind NordVPN.
Try NordLocker FreeZero-knowledge encryption · 8.7/10 · Free tier available