Crumbls
  • Services
  • About Us
  • Projects & Experiments
  • Blog
  • Documentation
  • Contact Us
  • Help Desk
  • Services
  • About Us
  • Projects & Experiments
  • Blog
  • Documentation
  • Contact Us
  • Help Desk
  1. Documentation
  2. /
  3. Sealcraft
  4. /
  5. Advanced

Sealcraft

Overview

  • Sealcraft
  • Changelog
  • Security Policy
  • License
  • Configuration
  • Events
  • Installation
  • Introduction
  • Testing
  • Troubleshooting

Adr

  • ADR-0001: Active-DEK uniqueness
  • ADR-0002: Per-row requires explicit backfill
  • Architecture Decisions

Api Reference

  • API Reference
  • Contracts
  • Exceptions
  • KeyManager

Providers

  • AWS KMS
  • Azure Key Vault
  • GCP Cloud KMS
  • HashiCorp Vault Transit
  • KEK Providers
  • Local Provider

Advanced

  • Advanced
  • Architecture
  • Ciphers
  • Moving columns from APP_KEY to Sealcraft
  • Performance
  • Threat Model

Key Management

  • Crypto-Shred
  • DEK Rotation
  • KEK Rotation
  • Key Management
  • Provider Migration

Encryption Contexts

  • Delegated Context
  • Encryption Contexts
  • Per-Column Override
  • Per-Group Strategy
  • Per-Row Strategy

Getting Started

  • Encrypted JSON
  • Getting Started
  • Model Integration

crumbls/sealcraft v1.4.0

Advanced

  • Architecture -- how KEK, DEK, and context flow through a request
  • Ciphers -- AES-256-GCM vs XChaCha20-Poly1305, when to switch
  • Threat model -- what Sealcraft protects against and what it does not
  • Performance -- cache hit paths, request-lifetime costs
  • Moving columns from APP_KEY to Sealcraft -- per-column adoption for apps already using the encrypted cast
View source on GitHub
Crumbls, LLC · Lafayette, CO 80026 · 303-909-3437 · contact@crumbls.com

Copyright © 2026 Crumbls, LLC. All rights reserved.

  • Privacy Policy
  • Terms of Service
  • Helpdesk