
GITNUXSOFTWARE ADVICE
Cybersecurity Information SecurityTop 10 Best Folder Protection Software of 2026
Top 10 folder protection software picks for enterprise DLP and secure sharing, with rankings and guidance for Google Drive Enterprise DLP.
How we ranked these tools
Core product claims cross-referenced against official documentation, changelogs, and independent technical reviews.
Analyzed video reviews and hundreds of written evaluations to capture real-world user experiences with each tool.
AI persona simulations modeled how different user types would experience each tool across common use cases and workflows.
Final rankings reviewed and approved by our editorial team with authority to override AI-generated scores based on domain expertise.
Score: Features 40% · Ease 30% · Value 30%
Gitnux may earn a commission through links on this page — this does not influence rankings. Editorial policy
My Lockbox is the best pick if teams need Windows folder encryption with controlled unlock on managed endpoints, whereas Bitdefender GravityZone fits enterprise shops that want folder protection governed from a single security console alongside ransomware defenses.
Editor’s top 3 picks
Three quick recommendations before you dive into the full comparison below — each one leads on a different dimension.
My Lockbox
Folder unlock flows with recovery-key support reduce permanent lockout risk for encrypted directories.
Built for fits when teams need Windows folder encryption plus controlled unlock on managed endpoints..
Folder Guard
Editor pickFolder protection profiles with both lock behavior and access-attempt logging per protected folder.
Built for fits when Windows admins need folder-granular access control and audit trails for sensitive local or shared drives..
Folder Lock
Editor pickVault-style encrypted container workflow with lock and unlock operations driven by the endpoint user.
Built for fits when single Windows users need local folder protection against casual access..
Related reading
- Cybersecurity Information SecurityTop 10 Best Folder Encryption Software of 2026
- Cybersecurity Information SecurityTop 10 Best File Protection Software of 2026
- Cybersecurity Information SecurityTop 10 Best Folder Locking Software of 2026
- Cybersecurity Information SecurityTop 10 Best Computer Protection Services of 2026
Comparison Table
Folder protection software manages local data risk by enforcing encryption, hide-and-unhide workflows, and permission controls at the folder and drive level. This ranked list is built for analysts and technical evaluators comparing control models like access restriction versus crypto-first approaches, with emphasis on auditability, deployment fit for enterprise secure sharing, and evidence-based comparisons led by Folder Guard.
My Lockbox
SMBMy Lockbox hides and password-protects folders on Windows computers.
Folder unlock flows with recovery-key support reduce permanent lockout risk for encrypted directories.
My Lockbox protects selected Windows folders by encrypting their contents so only authorized unlock actions can access data in clear form. The product centers on endpoint deployment and local governance for which folders are protected and how unlock permissions are handled. The workflow includes a recovery key path so locked folders can be restored without losing data after key loss.
A tradeoff is that folder protection is tied to endpoint setup, so policy drift across machines creates inconsistent protection coverage unless configuration is centrally managed. A good fit appears when a small IT team needs protected shared data areas on network drives while keeping encrypted artifacts resident on disk.
- +Client-side encryption for protected folders reduces exposure from plain storage
- +Recovery-key workflow supports restore after lost unlock credentials
- +Per-folder unlock controls target only selected directories
- +Access attempt logging helps trace unauthorized access attempts
- –Requires consistent endpoint setup to avoid partial protection coverage
- –Admin governance depends on how endpoint policies are distributed
- –Unlock access can add friction for high-frequency file workflows
IT security admins
Protects confidential Windows folder repositories
Encrypted data stays inaccessible by default
Compliance teams
Traces access attempts to locked folders
Improves incident evidence collection
Show 2 more scenarios
Legal operations staff
Safeguards case documents during handoffs
Reduces exposure during document movement
Keeps case files encrypted on endpoints while enabling authorized unlock for reviews.
Department managers
Limits access to shared directories
Access is constrained per directory
Applies folder-level protection so shared drives contain encrypted content without open access.
Best for: Fits when teams need Windows folder encryption plus controlled unlock on managed endpoints.
More related reading
Folder Guard
SMBFolder Guard restricts access to files, folders, drives, and Windows settings.
Folder protection profiles with both lock behavior and access-attempt logging per protected folder.
Folder Guard focuses on controlling and auditing access to specific folders by mapping protection settings to Windows security behavior. The product targets practical governance for Windows file shares and local folders by applying protected-folder rules without requiring a separate DLP workflow. Logging captures access attempts and administrative changes so teams can review policy enforcement outcomes after incidents.
A key tradeoff is that Folder Guard’s control model is Windows-focused, so teams with mixed endpoints or non-Windows storage need separate controls. It fits best when sensitive datasets live on NTFS paths and administrators want strong, folder-granular protection plus visibility into denied or permitted access.
- +Folder-granular permission enforcement for Windows folders
- +Access attempt logging for denied and permitted access
- +Lock actions that prevent unauthorized modification of protected folders
- +Local deployment supports endpoint-level governance without extra agents
- –Windows-centric coverage leaves non-Windows storage unaddressed
- –Centralized policy operations across fleets require consistent local admin practices
- –Granular rules can create admin overhead when many folders are protected
- –Protection boundaries align with NTFS paths, which complicates non-filesystem workflows
IT security administrators
Protect HR and finance folders
Fewer unauthorized edits
System administrators
Harden network share directories
Tighter share control
Show 2 more scenarios
Compliance owners
Maintain audit-ready folder access history
Clear enforcement evidence
Track changes to protected folders and capture access activity for investigations.
Endpoint operations teams
Reduce ransomware damage scope
Lower impact radius
Lock selected folders so unauthorized processes cannot modify protected content.
Best for: Fits when Windows admins need folder-granular access control and audit trails for sensitive local or shared drives.
Folder Lock
SMBFolder Lock encrypts, locks, hides, and backs up files and folders.
Vault-style encrypted container workflow with lock and unlock operations driven by the endpoint user.
Folder Lock provides a guided flow for creating protected folders and locking or unlocking them under a single access credential. Protected items are stored inside an encrypted container and presented only when the vault state is unlocked, which reduces casual data exposure on shared systems. Access attempt logging supports basic auditing for failed unlock or access operations, and tamper detection behavior depends on how the protected folder is handled during lock state.
The tradeoff is limited enterprise governance because Folder Lock does not provide an RBAC model or centralized policy management for fleets of Windows devices. A strong usage situation is a user-owner machine where one person needs quick protection for personal or departmental folders against casual browsing and accidental disclosure.
- +Straightforward lock and unlock workflow for protected folders
- +Encrypted container model hides file contents while locked
- +Basic access attempt logging for unlock and access failures
- +Works well for standalone Windows endpoint protection
- –No centralized management for multi-device deployment control
- –Limited auditing depth beyond unlock and access attempt events
- –Password recovery and key handling are less enterprise-friendly
- –Not suited for Drive-style or DLP network policy enforcement
Individual users on Windows
Protect personal project folders locally
Reduced accidental exposure
Office staff with shared desks
Prevent coworkers from browsing sensitive folders
Lower risk of casual snooping
Show 1 more scenario
Small team protecting departmental drafts
Secure locally stored working documents
Cleaner separation of drafts and access
Uses an encrypted container to safeguard folders during normal workstation use.
Best for: Fits when single Windows users need local folder protection against casual access.
Bitdefender GravityZone
enterpriseEnterprise endpoint security platform that includes folder and file protection modules.
GravityZone policy-driven protected-resource enforcement managed from the same console used for endpoint ransomware prevention.
Bitdefender GravityZone combines endpoint security with centralized policy controls that can extend folder protection into managed Windows and file-server scenarios. GravityZone’s value for folder protection comes from policy-based encryption and access controls driven through its security management console rather than per-endpoint manual setup.
Administrators can enforce consistent protection settings across groups and track security events tied to protected resources. The workflow integrates folder protection with broader ransomware prevention and endpoint hardening that can reduce time spent on separate tooling.
- +Centralized console supports consistent protection policy across many endpoints
- +Actionable security event visibility for protected resource access attempts
- +Works with managed endpoint hardening and ransomware prevention workflows
- +Group-based configuration reduces per-device customization effort
- –Folder protection settings can require careful policy design across endpoint groups
- –Integration with specific network file workflows may need lab validation
- –Large-scale rollouts depend on endpoint readiness and directory permission alignment
- –API and automation coverage for folder-level controls is narrower than DLP-first vendors
Best for: Fits when enterprise teams want folder protection governed from one security console alongside ransomware controls.
7-Zip
SMBOpen-source file archiver with AES-256 encrypted archive creation for folder protection.
Password-protected archive encryption with extract-time integrity checks for the encrypted payload inside a single container.
7-Zip creates and extracts 7z, ZIP, and other compressed archives with strong cross-file portability. Folder protection is implemented through password-protected archive encryption, which keeps encrypted contents in an application-controlled container.
It supports multiple encryption algorithms for archive payloads and optional integrity checks for common extraction workflows. Centralized access controls, audit logging, and policy enforcement for folders on a network share are not part of the core toolset.
- +Creates encrypted 7z and ZIP containers for file and folder bundling
- +Works offline with local archive encryption and integrity verification on extract
- +Supports varied encryption settings for archive-based protection workflows
- +Runs as a Windows application and supports automation through command-line use
- –No built-in folder lock controls using Windows or NTFS permissions
- –No native centralized policy management for multiple endpoints
- –No access attempt logging for encrypted container reads and failures
- –Automation relies on archive creation and extraction steps, not live access gating
Best for: Fits when teams need portable encrypted archives for occasional secure sharing, not continuous folder governance.
Wise Folder Hider
SMBWise Folder Hider hides and password-protects files, folders, and USB drives.
Per-folder hidden-folder workflow that combines visibility hiding with password-based access control.
Wise Folder Hider focuses on desktop folder lock via a hiding and protection workflow designed for local Windows users. It bundles password protection with folder visibility control to reduce casual access to sensitive directories.
The product primarily targets endpoint protection rather than drive-wide enterprise policy enforcement. Admin automation, API exposure, and centralized governance are not a primary strength compared with enterprise-grade secure sharing and DLP systems.
- +Quick folder hiding and password gating for local Windows directories
- +Lightweight workflow for protecting folders without complex admin setup
- +Clear per-folder protection scope that matches small, personal use cases
- +Decent friction reduction versus full secure vault deployments
- –No enterprise centralized management or RBAC for multi-user governance
- –Limited audit log depth for access attempt logging and investigations
- –Not designed for encrypted container models across SMB shares
- –Automation and API surface for provisioning and orchestration appear minimal
Best for: Fits when teams need basic endpoint folder hiding on Windows devices, not enterprise DLP or secure sharing.
Kakasoft Folder Protector
SMBLightweight Windows utility for password-protecting folders with AES-256 encryption.
Password-protected folder containers combined with enforced permission checks during access attempts.
Kakasoft Folder Protector focuses on Windows folder protection with local encryption and access controls rather than cloud-first sharing controls. It provides policy-driven folder access restrictions, file and folder permission enforcement, and optional password-based protection for protected containers.
Centralized management is designed for administrator-driven rollout across endpoints, with visibility into access attempts tied to protected resources. Cleanup and recovery workflows support removing or restoring protection after changes to folder assignments.
- +Endpoint-first folder protection for Windows file system permissions
- +Policy-based restriction of specific folders and subfolders
- +Password-based folder protection option for ad hoc access needs
- +Admin rollouts designed around protected folder assignments
- –Primarily Windows-centric, with limited value for non-Windows storage
- –Folder encryption coverage can be constrained by app-controlled access paths
- –Integration depth for external policy systems depends on available connectors
- –Richer audit exports require workflow planning instead of turnkey reports
Best for: Fits when enterprises need local folder access enforcement on Windows endpoints and basic recovery workflows.
Protect Folder
SMBWindows application for hiding and password-protecting individual folders.
Password-gated folder locking workflow with an unlock process designed for regular day-to-day access.
Protect Folder focuses on desktop folder protection with local encryption behavior and Windows-oriented access control workflows. The product emphasizes locking down specific folders and restricting modifications through an application-controlled protection layer.
It also provides a recovery-oriented workflow for getting back to protected content when keys or passwords are involved. Administration and integration depth are limited compared with enterprise DLP stacks designed for network shares and centralized governance.
- +Folder-specific protection targets user directories without encrypting entire drives
- +Direct password and unlock workflows reduce friction for ad hoc access needs
- +Protection behavior is practical for endpoint folders tied to Windows activity
- +Clear separation between protected and unprotected paths simplifies user behavior
- –Limited enterprise governance features for large user populations and roles
- –Integration and API surface are not positioned for DLP-style automation pipelines
- –Audit logging and tamper detection are not a primary workflow focus
- –Recovery management can require careful handling of unlock credentials
Best for: Fits when small teams need endpoint folder lock and password-based access without DLP integration.
Cryptomator
SMBCryptomator encrypts folders locally before they synchronize with cloud storage.
Zero-knowledge vault model with local unlock that decrypts to a mounted virtual volume per user device.
Cryptomator encrypts files and folders client-side inside an encrypted container that gets stored like regular data on local drives or cloud storage. It uses a zero-knowledge design where the encryption keys live on the endpoint, not on a server, so access control depends on device-side unlock and user credentials.
The core capability is a protected volume workflow that maps to decrypted files only when the vault is unlocked. Folder protection is implemented through cryptography over the entire vault contents rather than through server-managed folder permissions.
- +Client-side encryption keeps encryption keys off servers by default
- +Encrypted container format works over local storage and many cloud backends
- +Mount-and-unlock workflow supports normal file editing within a decrypted view
- +Cross-platform vault support covers Windows, macOS, and Linux
- –No centralized enterprise policy enforcement for encrypted folders
- –Access attempt logging and audit trails are limited to local event visibility
- –Folder-level sharing control is coarse compared with DLP-centric entitlement models
- –Key recovery and rotation require careful vault management by administrators
Best for: Fits when teams need client-side folder encryption over existing storage, without relying on centralized folder ACLs.
GiliSoft File Lock Pro
SMBGiliSoft File Lock Pro locks, hides, and encrypts files, folders, and drives.
Hides locked folders while enforcing access at the Windows endpoint, with access attempt logging tied to lock state.
GiliSoft File Lock Pro targets Windows folder lock and access control by applying protection directly to selected directories on the endpoint.
The product’s primary controls are lock state, optional folder hiding, and access attempt logging, which together cover casual viewing and basic monitoring.
Enterprise requirements like centralized policy enforcement, RBAC, and API-driven provisioning are not the focus of the feature set.
- +Simple folder lock workflow with quick enable and disable actions
- +Hidden locked folders reduce visibility for users who can browse drives
- +Access attempt logging supports basic monitoring of lock bypass attempts
- +Works with local Windows file locations without needing a server component
- –Limited enterprise governance features for centralized policies and rollbacks
- –No documented API surface for provisioning folders or integrating with IAM systems
- –Often relies on endpoint discipline because enforcement is local to Windows
- –Stronger prevention than recovery workflows when keys or passwords are lost
Best for: Fits when single-site teams need local folder protection on Windows endpoints without centralized administration.
Conclusion
After evaluating 10 cybersecurity information security, My Lockbox stands out as our overall top pick — it scored highest across our combined criteria of features, ease of use, and value, which is why it sits at #1 in the rankings above.
Use the comparison table and detailed reviews above to validate the fit against your own requirements before committing to a tool.
How to Choose the Right folder protection software
This buyer's guide covers folder protection software options that lock access to sensitive folders on endpoint storage, enforce folder-level rules, or package data into encrypted containers for secure sharing. The tools covered include My Lockbox, Folder Guard, Folder Lock, Bitdefender GravityZone, and 7-Zip, plus Wise Folder Hider, Kakasoft Folder Protector, Protect Folder, Cryptomator, and GiliSoft File Lock Pro.
The strongest enterprise fit in this set is My Lockbox when recovery-key support is needed to reduce permanent lockout risk for encrypted directories. Teams that want folder-granular access-attempt visibility on Windows should evaluate Folder Guard and Bitdefender GravityZone for policy enforcement from a centralized console used alongside ransomware controls.
Folder protection software for locked-access folders, encrypted containers, and access-attempt auditing
Folder protection software controls who can access specific directories by combining encryption, lock and unlock workflows, and access-attempt logging tied to the protected state. My Lockbox uses client-side encryption for protected folders and includes a recovery-key unlock workflow to restore access after lost unlock credentials. Folder Guard focuses on folder-granular permission enforcement for Windows folders and logs access attempts for denied and permitted access.
Other tools in the set emphasize different deployment shapes, like Folder Lock and Kakasoft Folder Protector with endpoint-driven container workflows and permission checks during access attempts. Several entries also shift the problem into portable encryption with 7-Zip password-protected archives or into a zero-knowledge vault model with Cryptomator mounted per device.
Folder protection evaluation features for locked access and encrypted containers
Folder protection software must enforce access at the folder boundary, not only when files are opened or copied. Tools in this set either control lock and unlock operations on the endpoint or package data into encrypted containers for controlled access.
The strongest enterprise signals are policy enforcement controls and traceability for access attempts tied to protected state. My Lockbox and Folder Guard both tie protection workflows to unlock or access-attempt logging, while Bitdefender GravityZone ties protected-resource enforcement into a centralized endpoint security console.
Recovery-key unlock workflow to prevent permanent lockout
My Lockbox supports recovery-key unlock flows for encrypted directories, which reduces the chance of irreversible access loss after lost unlock credentials. Folder Lock is centered on endpoint-driven lock and unlock with limited centralized management and audit depth.
Access-attempt logging tied to protected folders
Folder Guard provides access attempt logging for denied and permitted access per protected folder, which supports access investigation on Windows folders. Bitdefender GravityZone adds actionable security event visibility for protected resource access attempts from its centralized console.
Policy-driven governance from a centralized security console
Bitdefender GravityZone uses a single console to manage policy-driven protected-resource enforcement alongside endpoint ransomware prevention. My Lockbox central governance depends on how endpoint policies are distributed, which can require consistent endpoint setup across fleets.
Encryption container workflow built for portability and offline use
7-Zip creates password-protected encrypted 7z and ZIP containers that work offline and verify integrity on extract. Cryptomator uses a zero-knowledge vault model that decrypts to a mounted virtual volume per user device, which limits centralized policy enforcement.
Hidden-folder concealment combined with password gating
Wise Folder Hider runs a per-folder hidden-folder workflow that combines visibility hiding with password-based access control on Windows devices. GiliSoft File Lock Pro hides locked folders while enforcing access at the Windows endpoint and ties access attempt logging to lock state.
How to choose folder protection software by governance, enforcement, and unlock model
Start by selecting which control plane must own the policy. Some tools are endpoint-first with local lock and unlock workflows, while others centralize folder protection policy in an enterprise console used for broader security operations.
Then map the operational failure mode to the unlock model. Recovery-key workflows reduce lockout risk, while password-only or local-unlock models shift responsibility to user credential handling and device-specific access paths.
Choose centralized policy enforcement if fleet governance is required
Select Bitdefender GravityZone when protected-resource enforcement must be governed from the same console used for endpoint ransomware prevention. Use this path when Windows endpoints are managed in endpoint groups and protection settings must remain consistent.
Choose recovery-key unlock if lost credentials cannot cause downtime
Select My Lockbox when encrypted folder access must survive lost unlock credentials via recovery-key support. Avoid relying on endpoint-only unlock where management and audit depth remain limited for multi-device control.
Choose endpoint folder-granular enforcement with access-attempt logging for Windows
Select Folder Guard when folder-granular Windows permission enforcement and access-attempt logging per protected folder are required. Validate that non-Windows storage targets are not part of the enforcement scope.
Choose portable encrypted containers when the main requirement is controlled sharing
Select 7-Zip when secure sharing uses encrypted 7z or ZIP archives with extract-time integrity checks. Choose this path when continuous folder governance is not the primary goal.
Choose a per-user vault model when server-side key custody is a constraint
Select Cryptomator when encryption keys must stay off servers by default in a zero-knowledge vault model. Confirm that centralized enterprise policy enforcement for encrypted folders is not a hard requirement.
Choose password-gated locking or hiding only for local Windows use cases
Select Protect Folder, Wise Folder Hider, or GiliSoft File Lock Pro when the workflow is local endpoint folder lock, unlock, or hidden-folder access gating. This path fits small teams and single-site endpoints where centralized governance and RBAC are not the primary success criteria.
Who folder protection software is for in Windows-centric and enterprise scenarios
Teams need folder protection software when sensitive directories must resist casual access and when access attempts must be traceable. This buyer set spans endpoint policy enforcement for Windows and container-based encryption for portable sharing.
The right fit depends on whether the requirement is recoverability, logging depth, or centralized governance that aligns with existing endpoint administration.
Enterprise Windows security teams using an endpoint console for ransomware control
Bitdefender GravityZone fits when protected-resource enforcement must be governed from the same centralized console used for endpoint ransomware prevention. The tooling also provides security event visibility for protected access attempts.
IT admins who must prevent permanent lockout for encrypted directories
My Lockbox fits when recovery-key unlock workflows are needed to reduce the risk of permanent lockout after lost unlock credentials. Client-side encryption for protected folders reduces exposure from plain storage on managed endpoints.
Windows admins who require folder-level access-attempt logging and permission enforcement
Folder Guard fits when folder-granular permission enforcement and access attempt logging per protected folder are the main investigation and compliance needs. The product is Windows-centric, which aligns with local and shared drive targets on Windows.
Teams that need encrypted sharing via portable archives rather than always-on folder governance
7-Zip fits when secure sharing is built around password-protected encrypted 7z and ZIP containers with integrity checks on extract. This approach does not replace folder ACL governance controls.
Small teams managing single-site Windows endpoints without centralized governance demands
Protect Folder, Wise Folder Hider, and GiliSoft File Lock Pro fit when local password-gated locking or hidden-folder workflows are sufficient. These tools trade away enterprise governance controls and API-driven provisioning for simpler endpoint workflows.
Common mistakes when buying folder protection software
Mistakes usually come from assuming folder encryption or locking is always centrally governed and fully auditable. Many tools in this set focus on endpoint workflows or encrypted containers, which changes what can be controlled across devices.
Other mistakes come from mismatch between the required enforcement target and the product’s Windows-centric coverage.
Selecting a local unlock workflow without a recovery-key path
Avoid choosing tools that rely only on user password unlock when lost credentials would block access. My Lockbox includes recovery-key support for encrypted directories to reduce permanent lockout risk.
Assuming access logging covers denied and permitted attempts for every protected folder
Verify that the tool logs access attempts tied to the protected state, not only unlock events. Folder Guard logs denied and permitted access attempts per protected folder.
Using Windows-only folder enforcement where non-Windows storage is in scope
Confirm coverage for the storage platforms that must be protected, because Windows-centric products leave other targets unaddressed. Folder Guard and Kakasoft Folder Protector both emphasize Windows endpoint permission enforcement.
Treating encrypted archives as equivalent to folder governance controls
Recognize that 7-Zip encrypts data into password-protected 7z and ZIP containers rather than enforcing folder boundary access policies continuously. Folder governance needs endpoint policy enforcement and access attempt logging, which archives do not provide.
How We Selected and Ranked These Tools
We evaluated each option on folder-level control mechanisms that actually gate access, because My Lockbox uses client-side encryption plus a recovery-key unlock workflow for protected folders. We weighted features at 40% and used ease and value each at 30% to compare how quickly teams can deploy locking and unlock operations on endpoint storage.
We prioritized enterprise governance signals when available, because Bitdefender GravityZone manages protected-resource enforcement from the same console used for endpoint ransomware prevention. We ranked My Lockbox highest because recovery-key unlock reduces permanent lockout risk for encrypted directories and its endpoint-first encryption workflow is built around controlled unlock with recovery support.
Frequently Asked Questions About folder protection software
How do My Lockbox and Cryptomator handle access control for locked folders on endpoints?
Which tools are more suitable when folder protection must be governed from a central console for enterprise endpoints?
What breaks if 7-Zip is used for continuous folder governance instead of encrypted sharing?
When does Folder Guard’s Windows permissions approach work best compared to vault-style locking like Folder Lock?
How do Kakasoft Folder Protector and My Lockbox handle recovery after folder protection changes?
Which tools support access-attempt logging for protected content without relying on antivirus telemetry?
What should administrators expect from Wise Folder Hider and GiliSoft File Lock Pro regarding folder visibility and protection?
How do application-controlled workflows like Folder Lock differ from client-side encryption containers like Cryptomator?
Which tool fits ransomware-focused enterprise control bundles where folder protection is part of broader endpoint security policy?
Tools reviewed
Primary sources checked during evaluation.
Referenced in the comparison table and product reviews above.
Keep exploring
Comparing two specific tools?
Software Alternatives
See head-to-head software comparisons with feature breakdowns, pricing, and our recommendation for each use case.
Explore software alternatives→In this category
Cybersecurity Information Security alternatives
See side-by-side comparisons of cybersecurity information security tools and pick the right one for your stack.
Compare cybersecurity information security tools→