ccrypt encrypts single files with a passphrase using the AES-based Rijndael cipher. It replaces the file with an encrypted .cpt version.
ccencrypt file.txt # prompts twice; produces file.txt.cpt and removes file.txt
ccdecrypt file.txt.cpt # prompts; restores file.txt
ccdecrypt -c file.txt.cpt # decrypt to stdout, leaving the encrypted file alone
ccencrypt -K "$(cat keyfile)" file.txt # key from a file (avoid putting the key on the command line)
It is convenient for quick one-off protection. There is no key management, signing, or authenticated integrity check. For anything more serious, use GnuPG (gpg --symmetric) or age.