EntityFrameworkCore.Crypto.DataEncryption
10.6.5
dotnet add package EntityFrameworkCore.Crypto.DataEncryption --version 10.6.5
NuGet\Install-Package EntityFrameworkCore.Crypto.DataEncryption -Version 10.6.5
<PackageReference Include="EntityFrameworkCore.Crypto.DataEncryption" Version="10.6.5" />
<PackageVersion Include="EntityFrameworkCore.Crypto.DataEncryption" Version="10.6.5" />
<PackageReference Include="EntityFrameworkCore.Crypto.DataEncryption" />
paket add EntityFrameworkCore.Crypto.DataEncryption --version 10.6.5
#r "nuget: EntityFrameworkCore.Crypto.DataEncryption, 10.6.5"
#:package EntityFrameworkCore.Crypto.DataEncryption@10.6.5
#addin nuget:?package=EntityFrameworkCore.Crypto.DataEncryption&version=10.6.5
#tool nuget:?package=EntityFrameworkCore.Crypto.DataEncryption&version=10.6.5
EntityFrameworkCore.Crypto.DataEncryption
Official Links: Website & Licensing • The Complete Guide • Product Roadmap • Security & Threat Model
Transparent field-level encryption for EF Core 8, 9 and 10. AES-256-GCM AEAD, 100% in-process — zero plaintext leakage to the database, backups, or replication streams.
Install
dotnet add package EntityFrameworkCore.Crypto.DataEncryption
<PackageReference Include="EntityFrameworkCore.Crypto.DataEncryption" Version="10.6.5" />
Quick Start
// 1. Annotate your entity
public class Customer
{
public int Id { get; set; }
[CryptoEncrypted]
public string Ssn { get; set; } = string.Empty;
[CryptoEncrypted, Column(TypeName = "TEXT")]
public decimal AnnualSalary { get; set; }
}
// 2. Register in DbContext.OnModelCreating
var provider = new AesGcmCryptoProvider(LoadKeyFromSecureStore()); // 32-byte key
modelBuilder.UseEncryption(provider);
Enterprise Ready
| Capability | Detail |
|---|---|
| 🔒 Cryptography | AES-256-GCM AEAD — unique 96-bit nonce + 128-bit auth tag per write |
| ☁️ Cloud KMS | Azure Key Vault · AWS KMS · HashiCorp Vault with in-memory caching |
| 🔍 Searchable Encryption | HMAC-SHA256 blind indexing — native WHERE queries on encrypted columns |
| 🔄 Key Rotation | Zero-downtime versioned key rings, no migration downtime |
| 🤖 PII Detection | ML.NET classifier + deterministic detectors (Aadhaar, IBAN, SSN, Luhn) |
| 🚨 Anomaly Detection | Crypto Sentinel — SSA time-series exfiltration spike detection |
| 📬 Alerting | SMTP email + HMAC-signed Webhook + ILogger pipeline |
| 🕵️ Audit Trail | Row-level decryption log: who · what · when · IP via IDecryptionAuditSink |
| 📜 Compliance | Evidence packs for GDPR Art. 32 · India DPDP Act 2023 §8 · PCI-DSS |
| 🔭 Observability | OpenTelemetry metrics, ActivitySource tracing, startup health checks |
| ⚡ Async API | EncryptAsync / DecryptAsync on IEncryptionCryptoProvider |
| 🛡️ Auto-Encryption | Convention-based PII discovery with [DoNotEncrypt] opt-out |
Community plan — free for OSS & projects under $2,000/yr revenue. Includes encryption, KMS, key rotation, blind indexing, auto-encryption, and deterministic PII detectors.
Enterprise plan — $2,999/yr. Unlocks ML classifier, Crypto Sentinel, alerting, audit trail, compliance packs, and priority support (<1 business day SLA).
👉 View plans & get a license key
Documentation
| Doc | Description |
|---|---|
| Features & Plan Tiers | Full capability list, Community vs Enterprise |
| Configuration Guide | Cloud KMS, key rotation, blind indexing, sentinel, audit trail |
| Supported Types | All supported .NET types and column mappings |
| Complete Guide | In-depth API reference |
| Roadmap | Upcoming releases and feature specs |
| Security | Threat model and cryptographic design |
| Pricing & Licensing | Plans and enterprise support |
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- MailKit (>= 4.17.0)
- Microsoft.EntityFrameworkCore (>= 10.0.11)
- Microsoft.Extensions.Caching.Memory (>= 10.0.11)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.11)
- Microsoft.Extensions.Http (>= 10.0.11)
- Microsoft.Extensions.Options.DataAnnotations (>= 10.0.11)
- Microsoft.ML (>= 5.0.0)
- Microsoft.ML.TimeSeries (>= 5.0.0)
-
net8.0
- MailKit (>= 4.17.0)
- Microsoft.EntityFrameworkCore (>= 8.0.31)
- Microsoft.Extensions.Caching.Memory (>= 8.0.1)
- Microsoft.Extensions.Hosting.Abstractions (>= 8.0.1)
- Microsoft.Extensions.Http (>= 8.0.1)
- Microsoft.Extensions.Options.DataAnnotations (>= 8.0.0)
- Microsoft.ML (>= 5.0.0)
- Microsoft.ML.TimeSeries (>= 5.0.0)
-
net9.0
- MailKit (>= 4.17.0)
- Microsoft.EntityFrameworkCore (>= 9.0.20)
- Microsoft.Extensions.Caching.Memory (>= 9.0.20)
- Microsoft.Extensions.Hosting.Abstractions (>= 9.0.20)
- Microsoft.Extensions.Http (>= 9.0.20)
- Microsoft.Extensions.Options.DataAnnotations (>= 9.0.20)
- Microsoft.ML (>= 5.0.0)
- Microsoft.ML.TimeSeries (>= 5.0.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
Version 10.6.5:
- Embedded Source & Symbols: Embedded source mapping and GitHub repository links for seamless IDE navigation.
- Unified Package: Merged EntityFrameworkCore.Crypto.DataEncryption and ML into a single high-performance library.
- Core Features: AES-256-GCM AEAD, key rotation, blind-index search, deterministic encryption, and auto-encryption conventions.
- Enterprise Features: ML PII text classifier, Crypto Sentinel exfiltration alarm, multi-channel alerts (SMTP/Webhook), compliance evidence packs (DPDP/GDPR), and row-level decryption audit trail.
- Shipped: Decryption Audit Trail (IDecryptionAuditSink), Rich Types (decimal, double, long, JSON, Dictionary, Owned types), Async Provider Interface (EncryptAsync/DecryptAsync), OpenTelemetry metrics, and Startup Health Checks.
- Commercial Plans: Community (free under $2,000/yr), Enterprise ($2,999/yr), and 5-Year ($5,999 prepaid) at https://efcore-encryption.com/#plans.
- Upcoming Roadmap Milestones:
* v11.1 (Q3 2027): Multi-Tenant Cryptographic Key Isolation (ITenantKeyProvider)
* v11.2 (Q4 2027): Role-Based Dynamic Data Masking (IDataMaskingPolicy)
* v11.3 (Q1 2028): Fuzzy, Range & Prefix Searchable Encryption (Trigram Blind Indexing)
* v11.6 (Q4 2028): Zero-Downtime CLI Migration Tool (dotnet ef-crypto migrate)
* v12.1 (Q1 2029): Hardware Security Module Native Driver (PKCS#11 / YubiHSM / AWS CloudHSM)
Full roadmap & specifications: https://github.com/efcore-encryption/EntityFrameworkCore.Crypto.DataEncryption/blob/main/ROADMAP.md