Choose the protection you actually need
Finder permissions can discourage another standard user account from opening a folder, but they are not a substitute for encryption. FileVault encrypts the startup disk while the Mac is powered off or before login. An encrypted disk image protects selected files whenever that image is unmounted.
Use an encrypted local vault
- Collect the files in a suitable project or document folder.
- Create an AES-256 encrypted sparsebundle and store it somewhere with enough free space.
- Use a unique passphrase and save it in a trusted password manager.
- Copy the files into the mounted vault and verify them before removing the original.
- Unmount the vault when finished.
Why verification matters
A successful copy command is not enough evidence to remove the source. A careful workflow compares hierarchy, file types, sizes, symlinks, and regular-file bytes. Lock My Folders performs that verification before it asks macOS to move the original folder to Trash.
Keep a backup
Encryption protects confidentiality, not availability. A damaged sparsebundle, failed disk, accidental deletion, or forgotten passphrase can still make files unavailable. Back up important data before changing the original and keep a locked copy of the final vault.
Know the limits
Files are readable by your signed-in Mac session while the vault is unlocked. The app cannot recover a forgotten passphrase, repair a damaged disk, or replace FileVault, backups, malware protection, and good account security. Active sparsebundles in cloud-synced folders are not recommended.