Skip to main content

Class: EncryptionEngine

Defined in: src/security/Encryption.ts:15

Enterprise AES-256-GCM Authenticated Encryption Engine. Provides military-grade, tamper-evident field-level encryption for PCI-DSS, HIPAA, and enterprise PII compliance with zero external dependencies.

Constructors​

Constructor​

new EncryptionEngine(): EncryptionEngine

Returns​

EncryptionEngine

Methods​

setDefaultKey()​

static setDefaultKey(key): void

Defined in: src/security/Encryption.ts:21

Sets the global fallback encryption key.

Parameters​

ParameterType
keystring | Buffer<ArrayBufferLike>

Returns​

void


normalizeKey()​

static normalizeKey(key?): Buffer

Defined in: src/security/Encryption.ts:28

Resolves a 32-byte (256-bit) buffer key from string, buffer, or environment.

Parameters​

ParameterType
key?string | Buffer<ArrayBufferLike>

Returns​

Buffer


encrypt()​

static encrypt(text, options?): string | null

Defined in: src/security/Encryption.ts:56

Encrypts plaintext string using AES-256-GCM with a random 12-byte IV and 16-byte auth tag. Result format: enc:v1:<iv_hex>:<tag_hex>:<ciphertext_base64>

Parameters​

ParameterType
textstring | null | undefined
options?EncryptionOptions

Returns​

string | null


decrypt()​

static decrypt(payload, options?): string | null

Defined in: src/security/Encryption.ts:85

Decrypts an enc:v1:... ciphertext string back to plaintext. If the input is not encrypted or is plaintext, returns it unmodified. Throws Error if authentication tag validation fails (tamper detection).

Parameters​

ParameterType
payloadstring | null | undefined
options?EncryptionOptions

Returns​

string | null


isEncrypted()​

static isEncrypted(value): boolean

Defined in: src/security/Encryption.ts:131

Checks whether a value matches the encrypted envelope format.

Parameters​

ParameterType
valueunknown

Returns​

boolean