Class: EncryptionEngine
Defined in: src/security/Encryption.ts:15
Enterprise AES-256-GCM Authenticated Encryption Engine. Provides military-grade, tamper-evident field-level encryption for PCI-DSS, HIPAA, and enterprise PII compliance with zero external dependencies.
Constructors
Constructor
new EncryptionEngine():
EncryptionEngine
Returns
EncryptionEngine
Methods
setDefaultKey()
staticsetDefaultKey(key):void
Defined in: src/security/Encryption.ts:21
Sets the global fallback encryption key.
Parameters
| Parameter | Type |
|---|---|
key | string | Buffer<ArrayBufferLike> |
Returns
void
normalizeKey()
staticnormalizeKey(key?):Buffer
Defined in: src/security/Encryption.ts:28
Resolves a 32-byte (256-bit) buffer key from string, buffer, or environment.
Parameters
| Parameter | Type |
|---|---|
key? | string | Buffer<ArrayBufferLike> |
Returns
Buffer
encrypt()
staticencrypt(text,options?):string|null
Defined in: src/security/Encryption.ts:56
Encrypts plaintext string using AES-256-GCM with a random 12-byte IV and 16-byte auth tag.
Result format: enc:v1:<iv_hex>:<tag_hex>:<ciphertext_base64>
Parameters
| Parameter | Type |
|---|---|
text | string | null | undefined |
options? | EncryptionOptions |
Returns
string | null
decrypt()
staticdecrypt(payload,options?):string|null
Defined in: src/security/Encryption.ts:85
Decrypts an enc:v1:... ciphertext string back to plaintext.
If the input is not encrypted or is plaintext, returns it unmodified.
Throws Error if authentication tag validation fails (tamper detection).
Parameters
| Parameter | Type |
|---|---|
payload | string | null | undefined |
options? | EncryptionOptions |
Returns
string | null
isEncrypted()
staticisEncrypted(value):boolean
Defined in: src/security/Encryption.ts:131
Checks whether a value matches the encrypted envelope format.
Parameters
| Parameter | Type |
|---|---|
value | unknown |
Returns
boolean