local-first-privacy-encryption-sdk
Local-first client-side encryption SDK with AES-256-GCM, zero-knowledge key derivation and integrity checks.
| Size | Folder | Inside |
|---|---|---|
| 10.8 kB | src/ | 5 source files |
| 2.3 kB | examples/ | 1 example |
| 4 kB | tests/ | 1 test file |
| 19.7 kB | (root) | 14 docs · 3 config files |
| Size | Path |
|---|---|
| 30 B | .gitignore |
| 1.2 kB | AGENT_EVAL.md |
| 1.4 kB | ARCHITECTURE.md |
| 342 B | CHANGELOG.md |
| 435 B | DEPENDENCIES.md |
| 1.7 kB | LICENSE.md |
| 436 B | LIMITATIONS.md |
| 1.7 kB | PREVIEW.md |
| 1 kB | QUICKSTART.md |
| 3.4 kB | README.md |
| 715 B | SECURITY.md |
| 716 B | SUPPORT.md |
| 975 B | TEST_REPORT.md |
| 224 B | THIRD_PARTY_NOTICES.md |
| 761 B | THREAT_MODEL.md |
| 162 B | VERIFICATION.md |
| 1.3 kB | commercial-manifest.json |
| 2.3 kB | examples/demo.mjs |
| 669 B | package.json |
| 2.5 kB | release-manifest.json |
| 3.5 kB | src/archive.mjs |
| 3.3 kB | src/crypto.mjs |
| 1.3 kB | src/index.d.ts |
| 293 B | src/index.mjs |
| 2.4 kB | src/search.mjs |
| 4 kB | tests/crypto-privacy.test.mjs |
Already bought this?
View your purchasesREADME
Local-First Privacy & Encryption SDK
Zero-dependency Web Crypto envelope encryption, PBKDF2 portable archives, and client-side private search.
1. WHAT IS THIS?
The Local-First Privacy & Encryption SDK is a zero-dependency JavaScript/TypeScript library for web applications, browser extensions, and local-first software. It provides client-side envelope encryption (AES-GCM-256 with AES-KW key wrapping), passphrase-derived encrypted portable archives (PBKDF2-600,000 with SHA-256), and in-memory full-text search that executes entirely on the client without transmitting plaintext to backend servers.
2. WHO IS IT FOR?
- SaaS & Web3 Builders: Implementing end-to-end encryption (E2EE) where server infrastructure stores only ciphertext.
- Healthcare, Legal & FinTech Developers: Managing sensitive records subject to data sovereignty, minimization, and privacy compliance.
- Local-First Application Architects: Building offline-capable apps with secure local storage and backup exports.
3. WHAT PROBLEM DOES IT SOLVE?
Storing plaintext user data on centralized servers exposes businesses to catastrophic data breaches, subpoena exposure, and massive regulatory liability. Naive client-side encryption libraries frequently suffer from dependency bloat, vulnerable third-party cryptographic primitives, missing Additional Authenticated Data (AAD) binding, and insecure server-dependent search architectures.
4. WHY PAY FOR IT INSTEAD OF BUILDING IT?
- Native Web Crypto Standards: Uses native W3C Web Cryptography API (
crypto.subtle) available in modern browsers and Node.js 18+, eliminating third-party JS crypto attack surfaces. - Cryptographic Envelope Architecture: Encrypts records with ephemeral 256-bit AES-GCM data encryption keys (DEKs), wrapped with 256-bit AES-KW key encryption keys (KEKs) derived from a 32-byte root key via HKDF-SHA256.
- Explicit AAD Tenant Binding: Cryptographically binds tenant ID, record ID, and revision ID into the AEAD authentication tag to prevent ciphertext transplantation attacks.
- Hardened Portable Backup Archives: Exports state into self-contained JSON archives protected by PBKDF2-SHA256 (600,000 iterations default) with high-entropy salts.
- Zero-Leakage Local Search: Indexes and ranks decrypted documents locally using an in-memory TF-IDF/BM25-style scorer without sending search queries to any remote server.
- Zero External Dependencies: Built 100% on standard platform runtime APIs.
5. WHAT IS VERIFIED?
- 9 / 9 Automated Unit Tests Passed: Roundtrip envelope encryption/decryption, ciphertext tampering rejection, PBKDF2 archive roundtrip, passphrase length and wrong passphrase rejection, client-side private search ranking, buffer zeroization, wrong root key rejection, tampered AAD rejection, and empty search edge cases.
- Clean-Environment Isolation: 100% pass in an isolated temporary environment with zero external dependencies.
6. HOW DO I RUN IT?
# 1. Run unit test suite
node --test tests/crypto-privacy.test.mjs
# 2. Run interactive encryption and search demonstration
node examples/demo.mjs
Security scan report
Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from Socket are listed below.
- secrets
- none found
- X402 Git
- size limits
- within caps
- X402 Git
- known malware
- no dependency manifests to check
- OSV
- known vulnerabilities
- no dependency manifests to check
- OSV
- dependency behaviour
- nothing on a direct dependency · 1 in transitive packages
- Socket
- instruction smuggling
- none found
- X402 Git
- what it can do
- nothing to declare
- X402 Git
What this can do
links to 1 host in its docs · nothing runs at install
Findings (1)
- LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
Releases 1
- v1.0.02026-09-16
release: v1.0.0 commercial source edition