Protection on your terms
Start with a profile, then refine the available options. Preview the plan before committing to a build.
Turn your Lua source into code that’s harder to read, with precise controls and a clear view of every transformation.
Lua 5.4 available now. More languages are planned.
local function greet(name) return "Hello, " .. nameend print(greet("world"))A considered workflow, from the first line of source to the output you ship.
Start with a profile, then refine the available options. Preview the plan before committing to a build.
Bring your source, adjust your settings, inspect the output, and download the result from one focused screen.
Build reports show applied and skipped transformations, warnings, and size. Understand the result before you use it.
Paste your code or open a source file.
Choose a profile and review the protection plan.
Review your output and test it in your application.
GhostX targets standalone Lua 5.4. Other dialects and embedded hosts need their own compatibility testing.
Obfuscation makes source harder to read and analyze. It is not encryption or an absolute barrier to reverse engineering. Keep secrets outside code you distribute.
Your source is sent to the backend only when you preview or obfuscate. It is transformed without being executed, and temporary processing files are cleaned up after each request.
Start with Balanced, review the plan, then test the output. Compatibility uses conservative transforms; Strong includes experimental features.
Open the workspace and make your first protected build.
Practical protection, explicit controls, and results you can inspect.
Edit Lua, import UTF-8 files, preview a plan, and compare your source with generated output. Copy or download the result without leaving the editor.
Compatibility, Balanced, and Strong provide different starting points. Each build reports the transformations applied and skipped.
Combine identifier renaming and string or control-flow transformations where the selected profile and source permit. Experimental features are clearly identified.
Read the plan and build report. Inspect transform decisions, warnings, and source/output size before testing the result in your application.
The right protection depends on your code and runtime. Review and test each build.
Conservative transformations
A practical starting point
Additional experimental features
Start with a plan, then build when you’re ready.
Configure your protection. Preview the plan. Make it your build.
Prepare your source here. Sign in to preview and build.
Profile defaults apply unless you override a feature. Strong and VM features are experimental.
Use the profile default, apply a transform where supported, or require it. A required transform stops the build if it cannot be applied.
Rename local identifiers while preserving bindings.
Transform eligible string literals.
Restructure eligible control flow.
Transform statically resolved internal field names.
Share eligible literals through a generated pool.
Add indirection for eligible calls.
Outline eligible regions into functions.
Rewrite eligible numeric expressions.
Transform eligible constant conditions.
Experimental. Flatten eligible control-flow regions.
Experimental. Apply VM protection to eligible regions.
Drop a .lua or .txt file here, or choose a file. Maximum 1 MiB.
No file selectedAdd source, choose your settings, and click Obfuscate code.
UTF-8 Lua source, up to 1 MiB. Your source is processed on the server when you preview or obfuscate. Download your draft before closing this tab.
Practical notes on protecting your work, product updates, and what comes next.
Manage your content, accounts, and site activity.
A clear home for your organizations and projects.
Your recent previews and protected builds, in one place.
The details that make this workspace yours.
Enter your details to continue.
Start with your email and a strong password.
Enter the verification code sent to your inbox.
Request a code to recover access to your account.
Enter your reset code and choose a new password.
Live email delivery is awaiting validation. Registration and recovery requests do not confirm whether an account exists.
Protect your code and manage your projects.
Bring your source, choose your settings, and build.
Organize your projects and workspaces.
Review your recent previews and protected builds.
Manage your account details.
Manage access on this browser or sign out of all GhostX sessions.
Checking your session…
Manage your authenticators and verify access to sensitive actions.
Understand what stays on your device and how access is managed.
Sign-in uses an HttpOnly browser cookie. Provider tokens are kept encrypted on the server and never exposed to page scripts.
Manage accountSign out of this browser or revoke all GhostX browser sessions from your account. Unconfirmed provider sign-out can block new sign-ins until an operator resolves it.
Language, appearance, and sidebar preferences are saved on this device. Signed-in preferences are also saved to your account. No analytics or third-party page scripts are used.
Protection runs on the backend without executing your source. Review the report, download your protected code, and test it in your application.
Current service availability and connection checks.
Code protection
Source is processed by the backend after you sign in and choose Preview or Obfuscate.
Protection service
Account service
Prepare source, inspect a plan, and download protected Lua.
Confirmation and password recovery delivery await validation.
A few simple choices for a workspace that feels right.
Choose a light, dark, or system-matched workspace.
Set the language used throughout the workspace.
Manage your sign-in and active session from your account.
How GhostX.pro handles your information.
GhostX.pro operates this preview. A verified privacy contact and final retention schedule must be configured before public launch. This notice describes the current implementation.
Your draft is held in browser memory. Opening a file does not upload it. Clicking Preview plan or Obfuscate sends the source and chosen settings to the GhostX backend. Temporary processing files are removed after the request. Source is parsed and transformed without being executed. Downloaded files remain on your device until you remove them.
Signing in sends your email and password through the GhostX account server to Supabase Auth. GhostX stores account identifiers, encrypted provider tokens, session digests, and security metadata to authenticate requests and manage access. Passwords and provider tokens are not returned to the page.
A necessary HttpOnly cookie maintains your signed-in session. Language, appearance, and sidebar preferences use local storage and may be saved to your account when signed in. This website has no analytics, advertising trackers, or third-party page scripts.
Supabase provides the hosted account database and authentication service. Account and session records remain subject to operator-managed retention; there is no published automatic account-deletion schedule yet. Build workspace cleanup is separate from account records. Public retention terms and applicable transfer information remain launch requirements.
You can clear a draft, remove downloaded files, change browser preferences, and sign out locally or everywhere through your account. Clearing browser data does not delete hosted account records. Depending on applicable law, you may have rights to access, correct, delete, restrict, object to processing, or obtain a copy of personal data.
The operator is GhostX.pro. The supplied domain does not establish a monitored support inbox. A verified channel for privacy requests will be published before public release. Material changes to this notice will be reflected on this page.
The conditions for using the GhostX.pro preview.
These preview terms describe the current GhostX.pro software experience. Public service terms, operator contact details, and any jurisdiction-specific conditions must be finalized before public release. Paid subscriptions and payment processing are not offered in this version.
You retain your rights in the source you provide and the output produced from it, subject to the rights of others. Use GhostX only for code you own or are authorized to transform. You are responsible for complying with applicable licenses and distribution requirements.
GhostX transforms supported Lua source and provides plans, reports, and output. It targets standalone Lua 5.4. Other runtimes or hosts require separate validation. Certain advanced and Strong-profile features are experimental and are identified in the product.
Keep an original copy of your source and test generated output before distribution. Obfuscation raises the effort needed to understand code; it does not guarantee secrecy, prevent all reverse engineering, or replace access controls. Never embed credentials or other secrets in distributed code.
Keep account credentials private and use the session controls if access is compromised. Do not use another person’s account without authorization. Recovery and email-confirmation delivery remain subject to the published service availability.
This preview is available on localhost while public deployment is pending. Features may change as validation progresses. The status page identifies unavailable capabilities. No uptime commitment or paid service entitlement is created by this preview.
Follow the acceptable-use policy and applicable law. Do not disrupt the service, attempt unauthorized access, or use it to conceal harmful software. A verified operator contact must be published before the public service launches. Nothing here excludes rights that cannot lawfully be excluded.
Use the tools responsibly. Respect other people’s code.
Use GhostX to transform Lua code that you own or have permission to modify. Legitimate protection of your software, learning, and authorized testing are within the intended scope.
Do not misrepresent ownership, remove licensing obligations, distribute stolen source, or use obfuscation to conceal infringement. Protect only what you have the right to protect.
Do not use the service to conceal malware, credential theft, unauthorized surveillance, exploit delivery, or other harmful activity. Do not use generated code to gain unauthorized access or evade security controls on systems you do not own or administer.
Do not overload endpoints, bypass access or resource limits, probe accounts without authorization, or interfere with other users. Report suspected vulnerabilities responsibly without exposing another person’s data.
GhostX.pro may restrict access to protect the service or comply with applicable law. A verified abuse and security reporting channel must be configured before public launch. Preserve only the minimum information needed to describe an issue; do not include secrets or another person’s source.
The link may have changed. Head home or jump back into your workspace.