EntityFrameworkCore.Crypto.DataEncryption 10.6.5

dotnet add package EntityFrameworkCore.Crypto.DataEncryption --version 10.6.5
                    
NuGet\Install-Package EntityFrameworkCore.Crypto.DataEncryption -Version 10.6.5
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="EntityFrameworkCore.Crypto.DataEncryption" Version="10.6.5" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="EntityFrameworkCore.Crypto.DataEncryption" Version="10.6.5" />
                    
Directory.Packages.props
<PackageReference Include="EntityFrameworkCore.Crypto.DataEncryption" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add EntityFrameworkCore.Crypto.DataEncryption --version 10.6.5
                    
#r "nuget: EntityFrameworkCore.Crypto.DataEncryption, 10.6.5"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package EntityFrameworkCore.Crypto.DataEncryption@10.6.5
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=EntityFrameworkCore.Crypto.DataEncryption&version=10.6.5
                    
Install as a Cake Addin
#tool nuget:?package=EntityFrameworkCore.Crypto.DataEncryption&version=10.6.5
                    
Install as a Cake Tool

EntityFrameworkCore.Crypto.DataEncryption

.NET NuGet Downloads License Crypto Execution EF Core GDPR DPDP PCI-DSS

Official Links: Website & Licensing • The Complete Guide • Product Roadmap • Security & Threat Model

Transparent field-level encryption for EF Core 8, 9 and 10. AES-256-GCM AEAD, 100% in-process — zero plaintext leakage to the database, backups, or replication streams.


Install

dotnet add package EntityFrameworkCore.Crypto.DataEncryption
<PackageReference Include="EntityFrameworkCore.Crypto.DataEncryption" Version="10.6.5" />

Quick Start

// 1. Annotate your entity
public class Customer
{
    public int Id { get; set; }

    [CryptoEncrypted]
    public string Ssn { get; set; } = string.Empty;

    [CryptoEncrypted, Column(TypeName = "TEXT")]
    public decimal AnnualSalary { get; set; }
}

// 2. Register in DbContext.OnModelCreating
var provider = new AesGcmCryptoProvider(LoadKeyFromSecureStore()); // 32-byte key
modelBuilder.UseEncryption(provider);

Enterprise Ready

Capability Detail
🔒 Cryptography AES-256-GCM AEAD — unique 96-bit nonce + 128-bit auth tag per write
☁️ Cloud KMS Azure Key Vault · AWS KMS · HashiCorp Vault with in-memory caching
🔍 Searchable Encryption HMAC-SHA256 blind indexing — native WHERE queries on encrypted columns
🔄 Key Rotation Zero-downtime versioned key rings, no migration downtime
🤖 PII Detection ML.NET classifier + deterministic detectors (Aadhaar, IBAN, SSN, Luhn)
🚨 Anomaly Detection Crypto Sentinel — SSA time-series exfiltration spike detection
📬 Alerting SMTP email + HMAC-signed Webhook + ILogger pipeline
🕵️ Audit Trail Row-level decryption log: who · what · when · IP via IDecryptionAuditSink
📜 Compliance Evidence packs for GDPR Art. 32 · India DPDP Act 2023 §8 · PCI-DSS
🔭 Observability OpenTelemetry metrics, ActivitySource tracing, startup health checks
⚡ Async API EncryptAsync / DecryptAsync on IEncryptionCryptoProvider
🛡️ Auto-Encryption Convention-based PII discovery with [DoNotEncrypt] opt-out

Community plan — free for OSS & projects under $2,000/yr revenue. Includes encryption, KMS, key rotation, blind indexing, auto-encryption, and deterministic PII detectors.
Enterprise plan — $2,999/yr. Unlocks ML classifier, Crypto Sentinel, alerting, audit trail, compliance packs, and priority support (<1 business day SLA).
👉 View plans & get a license key


Documentation

Doc Description
Features & Plan Tiers Full capability list, Community vs Enterprise
Configuration Guide Cloud KMS, key rotation, blind indexing, sentinel, audit trail
Supported Types All supported .NET types and column mappings
Complete Guide In-depth API reference
Roadmap Upcoming releases and feature specs
Security Threat model and cryptographic design
Pricing & Licensing Plans and enterprise support
Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 is compatible.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
10.6.5 33 10/5/2026
10.6.0 223 9/10/2026
10.5.0 116 9/8/2026
10.0.1 4,507 11/12/2025
10.0.0 3,976 11/12/2025 10.0.0 is deprecated because it has critical bugs.
9.0.0 888 6/23/2025
8.0.3 69,285 5/29/2024
8.0.2 413 5/27/2024
8.0.1 393 5/27/2024
8.0.0 441 5/24/2024 8.0.0 is deprecated because it is no longer maintained.

Version 10.6.5:
- Embedded Source & Symbols: Embedded source mapping and GitHub repository links for seamless IDE navigation.
- Unified Package: Merged EntityFrameworkCore.Crypto.DataEncryption and ML into a single high-performance library.
- Core Features: AES-256-GCM AEAD, key rotation, blind-index search, deterministic encryption, and auto-encryption conventions.
- Enterprise Features: ML PII text classifier, Crypto Sentinel exfiltration alarm, multi-channel alerts (SMTP/Webhook), compliance evidence packs (DPDP/GDPR), and row-level decryption audit trail.
- Shipped: Decryption Audit Trail (IDecryptionAuditSink), Rich Types (decimal, double, long, JSON, Dictionary, Owned types), Async Provider Interface (EncryptAsync/DecryptAsync), OpenTelemetry metrics, and Startup Health Checks.
- Commercial Plans: Community (free under $2,000/yr), Enterprise ($2,999/yr), and 5-Year ($5,999 prepaid) at https://efcore-encryption.com/#plans.
- Upcoming Roadmap Milestones:
 * v11.1 (Q3 2027): Multi-Tenant Cryptographic Key Isolation (ITenantKeyProvider)
 * v11.2 (Q4 2027): Role-Based Dynamic Data Masking (IDataMaskingPolicy)
 * v11.3 (Q1 2028): Fuzzy, Range & Prefix Searchable Encryption (Trigram Blind Indexing)
 * v11.6 (Q4 2028): Zero-Downtime CLI Migration Tool (dotnet ef-crypto migrate)
 * v12.1 (Q1 2029): Hardware Security Module Native Driver (PKCS#11 / YubiHSM / AWS CloudHSM)
 Full roadmap & specifications: https://github.com/efcore-encryption/EntityFrameworkCore.Crypto.DataEncryption/blob/main/ROADMAP.md