What is AES-256-GCM?
In short:
AES-256, the Advanced Encryption Standard with a 256 bit key, is the strongest symmetric cipher in general use. Banks, governments and intelligence services protect their own secrets with it. TaskNote runs it in GCM mode, which makes it fast and also notices if anyone has tampered with your data.
🏛️ The safe
If your encryption key is the physical key, then AES-256-GCM is the design of the safe it opens.
- AES: a safe made of material that cannot be drilled, melted or blown open.
- 256: the thickness of the walls. This is the thickest available.
- GCM: an alarm built into the safe. Scratch the paint or alter anything while it is locked, and it goes off at once. The proper name for that is an integrity check.
🧮 How strong is 256 bits, really
The number is hard to picture, because human intuition was not built for it.
To break a single AES-256 key by trying every combination, you would need a machine drawing the energy of a star.
- Combinations: about 115 followed by seventy five digits.
- Time: every computer on Earth working together would still need longer than the universe has existed.

So when we say the data is safe, that is not optimism. It is arithmetic.
⚡ Why GCM mode
Not all AES is alike. Plenty of older software uses AES-CBC, which is slower and has had a long history of implementation mistakes.
TaskNote uses AES-256-GCM for two reasons:
- Speed. GCM encrypts several parts of a file at once, across the cores your device already has. That is why large notes still open instantly.
- Tamper detection. GCM carries its own check. Change a single bit of an encrypted note in transit, whether to corrupt it or to slip something in, and decryption refuses to proceed.
🛡️ How we use it
AES-256-GCM reaches TaskNote through the Web Crypto API.
Which means we do not run slow JavaScript to encrypt your notes. We call the cryptography engine already built into your browser.
- It is accelerated in hardware.
- It has been reviewed by the security teams at Google, Mozilla and Apple.
- It runs entirely on your device, client side.
❓ Questions people ask
Can a quantum computer break AES-256?
Not today, and not for a long while. Quantum computing threatens other families of cryptography, RSA in particular. A 256 bit symmetric key is expected to hold for decades.
Is AES-256 slower than AES-128?
Technically, by something like a third. On a modern processor the difference is measured in nanoseconds, which nobody can feel, so we took the stronger key.
Did you write your own encryption?
No, and we never will. Rolling your own cryptography is the first thing every security guide tells you not to do. We use the standard, audited implementation the browser provides.