How Secure is XLS Padlock?

KenPascoe

New member
Howdy All

Been hunting through the web site for details on the level of encryption and security in the XLS Padlock product and .xlsc file - but can’t seem to find anything. Can you point me towards that please so I can pass this along ot my client?

Thanks, Ken
 
Encryption used derived from Blowfish. We use limited key sizes due to restrictions in our country.
Excel’s own password encryption based on AES can also be used.
Note that any application running offline can be cracked nowadays, but it is still not an easy task.
A hacker could in theory disassemble the EXE made with XLS Padlock to retrieve the different encryption keys, which are also different for each EXE and based on the application secret key you enter in XLS Padlock. But we ensured to make reverse engineering highly difficult by obfuscating a lot of our sensitive code, based on code virtualization (that means the sensitive pseudo-code is run by internal virtual machines and it is not in common pure assembler).
That’s the same technique as we use for our VBA compiler.
So, basically a hacker would have to study the different virtual machines in order to learn how they work before he could start understanding the original code.
That’s also why our EXE files are so large compared to the original workbook file.
Few “professional” hackers with very strong knowledge should still be able to crack the program, but they generally have more appealing challenges than cracking a secured workbook. Except if your workbook sells for millions, but in that case, you should look for another security solution than a mere 140 EUR solution.
In other terms, you should be OK for a very long time, but we cannot give you a 100% safety guarantee.
Just also search for “XLS Padlock crack” and you will only find hawks or disguised malware. It’s not that our software is not crackable, it’s just difficult to do it and, as said before, it requires time, knowledge and resources.

Edit (October 2026): this answer describes XLS Padlock in 2020 and is out of date. Blowfish is no longer used: encryption is now based on AES. See the updated answer below.
 
Last edited:
Perfect, thanks. I just need to reassure my client - there are a couple bad, very old, reviews out there.
 
Howdy

Far out - just spent 30 minutes going through my browser history, including search results from when I started on this in April. Either it’s gone now (a few dead links) or I just can’t find it. As I recall it was a post in a user forum of a few hundred lines across at least 5 different products; XL Padlock and Lock XLS were included (which is how I came across it, searching for “Compare Lock XLS vs XLS Padlock”) and it was dated something like 2009.

But now - can’t find it at all. Which is probably a good thing.

Ken
 
Update (October 2026): how XLS Padlock protects your workbook today

The answer above dates from 2020. Here is the current picture, as of XLS Padlock 2026.3.

Blowfish is no longer used. Encryption is now based on AES:

  • save files are encrypted with AES 256, with HKDF-SHA256 key derivation and an HMAC-SHA256 tamper check;
  • the workbook, its embedded data and the compiled VBA bytecode are stored in an encrypted container inside the EXE, with an independent keystream for each embedded file and an HMAC-SHA256 integrity check over the whole container. The workbook is never written to disk in plaintext.

The other layers:

  • the VBA code you select is compiled to bytecode and its source is removed, so the VBA editor does not contain this VBA code anymore at runtime;
  • the formulas you choose are encrypted and evaluated at runtime;
  • the EXE checks its own integrity at startup and probes for common debuggers;
  • hardware-locked keys bind a license to a fingerprint built from several hardware and Windows identifiers (SHA-256 with the enhanced fingerprint);
  • online activation responses can be signed with Ed25519 (since 2026.0), so they cannot be forged, even by someone who intercepts the connection.

What has not changed since 2020: no protection that runs offline on your customer's computer can honestly be called unbreakable. The goal is to make extracting your workbook, formulas and code cost far more than it is worth, and each layer above adds to that cost.

For a client or a security review, the Security page lists every layer and the cryptographic primitives behind it.
 
Back
Top