Encryption as a Service, without the AWS/GCP setup 0 ▲ Levi Durfee 5 hours ago · Tech · hide · 0 comments I built an encryption service. It's called rypt, and it's backed by GCP Cloud KMS. Use coupon code LMDBLOG26 for 15% off any service for as long as you maintain an active subscription. A while back I wrote about envelope encryption. I still think it's important. But setting up a KMS, IAM roles, key rings, and audit logging just to encrypt some user data is a lot. Especially if you're one person or a small team. I wanted something where you sign up, get a key, and make a curl request. So that's what rypt is. You send data over HTTPS, and you get ciphertext back. You can also use envelope mode, where you generate a DEK yourself and only send the DEK to rypt to wrap. Then your actual data never leaves your server. Every operation gets logged. The log has the timestamp, key, key version, operation, result, request ID, and the caller's IP. You can export it. I think if you're going to trust someone with your keys, you should be able to see exactly what's being done with them. There are… No comments yet. Log in to reply on the Fediverse. Comments will appear here.