Support Me ☕

OfPlanet

Select Language:

Ck0fy.LocalVault: The Ultimate Local Data & File Encryption Library for .NET 8

1. What is Ck0fy.LocalVault?

Ck0fy.LocalVault is an advanced, high-performance security library built specifically for .NET 8 desktop applications (such as WinForms). It provides robust local data and file protection utilizing industry-standard AES-256-GCM encryption combined with OS-level hardware protection via Windows DPAPI.

2. Who is it for?

It is tailored for software developers and engineers who need to secure sensitive user data, application logs, caches, and configuration files locally against device theft, malware, and unauthorized local snooping—all without burdening end-users with manual passwords.

3. Supported File & Data Types

The library seamlessly secures any type of local asset on disk, including:

  • Images & Documents: Personal or confidential images (.png, .jpg), text files, and documents (.txt, .pdf, .docx).
  • Media Files: Private audio tracks or media recordings (.mp3, .wav).
  • Databases & Settings: Application caches, configuration JSONs, or lightweight databases (.db, .json, .config).

4. How to Use: Simple vs. Advanced Methods

The library offers intuitive APIs tailored for clean implementation:

A. Simple Usage (Default Vault):

// Encrypt & Decrypt a quick text string
string encrypted = await LocalVault.EncryptAsync("MySecretPassword123");
string decrypted = await LocalVault.DecryptAsync(encrypted);

// Protect & Unprotect a file (Image, Audio, or Document)
await LocalVault.ProtectFileAsync("photo.png", "photo.png.enc");
await LocalVault.UnprotectFileAsync("photo.png.enc", "photo_restored.png");

B. Advanced Usage (Custom Alias / Key Isolation):

// Isolate data using a custom alias option
var options = new VaultOptions { CustomAlias = "FinanceDepartment" };

// Protect text or files with the custom vault key
string encrypted = await LocalVault.EncryptAsync("SensitiveData", options);
await LocalVault.ProtectFileAsync("report.xlsx", "report.xlsx.enc", options);

// Restore data using the same custom alias options
string decrypted = await LocalVault.DecryptAsync(encrypted, options);
await LocalVault.UnprotectFileAsync("report.xlsx.enc", "report_restored.xlsx", options);

5. Developer Note

Device-Bound Security: Encrypted payloads are bound to the local user's operating system environment. They provide elite local protection and cannot be decrypted if moved to an unauthorized machine.