Skip to main content

EFSF Python SDK

The official Python SDK for the Ephemeral-First Security Framework.

Installation

# Basic installation
pip install efsf

# With Redis backend support
pip install efsf[redis]

# With all optional dependencies
pip install efsf[all]

Quick Start

from efsf import EphemeralStore, DataClassification

# Create a store (defaults to in-memory for development)
store = EphemeralStore()

# Store sensitive data with automatic TTL and encryption
record = store.put(
    data={"user_id": "123", "ssn": "xxx-xx-xxxx"},
    ttl="30m",  # Destroyed in 30 minutes
    classification=DataClassification.PII,
)

print(f"Stored record: {record.id}")
print(f"Expires at: {record.expires_at}")

# Retrieve while valid
data = store.get(record.id)
print(f"Retrieved: {data}")

# Check remaining time
remaining = store.ttl(record.id)
print(f"Time remaining: {remaining}")

# Manually destroy early
certificate = store.destroy(record.id)
print(f"Destruction certificate: {certificate.certificate_id}")

Using Redis Backend

from efsf import EphemeralStore

store = EphemeralStore(
    backend="redis://localhost:6379/0",
    default_ttl="1h",
    attestation=True,
)

# Redis provides native TTL enforcement
record = store.put({"session": "data"}, ttl="15m")

Sealed Execution

from efsf import sealed

@sealed(attestation=True)
def process_payment(card_number: str, amount: float) -> str:
    """
    All local variables are destroyed when this function returns.
    A destruction certificate is automatically generated.
    """
    # Process payment...
    return f"payment_id_{hash(card_number) % 10000}"

result = process_payment("4111-1111-1111-1111", 99.99)
# card_number is now destroyed from memory

Data Classifications

Classification Default TTL Max TTL Use Case
TRANSIENT 1 hour 24 hours Session tokens, OTPs
SHORT_LIVED 1 day 7 days Shopping carts, temp files
RETENTION_BOUND 90 days 7 years Invoices, audit logs
PERSISTENT None None Legal holds (requires justification)

Destruction Certificates

Every destroyed record can have a cryptographically signed certificate:

from efsf import EphemeralStore

store = EphemeralStore(attestation=True)
record = store.put({"sensitive": "data"}, ttl="1m")

# Wait for expiration or destroy manually
certificate = store.destroy(record.id)

# Certificate contains:
print(certificate.to_json())
# {
#   "certificate_id": "uuid",
#   "resource": {"type": "ephemeral_data", "id": "record-id", ...},
#   "destruction": {"method": "crypto_shred", "timestamp": "...", ...},
#   "chain_of_custody": {...},
#   "signature": "base64-signature"
# }

Development

# Clone the repo
git clone https://github.com/akshat666/ephemeral-first-security-framework.git
cd efsf/sdk/python

# Install dev dependencies
pip install -e ".[dev]"

# Run tests
pytest

# Run tests with Redis (requires running Redis)
pytest --redis-url redis://localhost:6379

# Type checking
mypy efsf/

# Formatting
black efsf/ tests/

License

Apache 2.0

Metadata

Release files for efsf 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for efsf 0.3.0
File Size Uploaded
efsf-0.3.0.tar.gz 21.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for efsf 0.3.0
File Interpreter ABI Platform
efsf-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 41.2 kB

Release files / efsf-0.3.0.tar.gz

Download URL efsf-0.3.0.tar.gz
Size 21.4 kB
Tags Source
SHA-256 checksum
How to use checksums
82b154c4b447da5352ed3d4082b57cf68c7ef46e3c52876eccc70383d55ac4fc
BLAKE2b-256 checksum
How to use checksums
e2af16909e278c2d472c91f4e842b94947fb6acfe276c0fd8e801a4734569544
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 31, 2026.

Transparency log

Release files / efsf-0.3.0-py3-none-any.whl

Download URL efsf-0.3.0-py3-none-any.whl
Size 19.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
de4f84230d530f4a7f58645bdb289e5657ea89c0b857228729ef4933a46699a0
BLAKE2b-256 checksum
How to use checksums
9fc3910b785e69c3555b29958b8f96c66123bfa5fcc1d742ad5ccf1a05f9ca2c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 31, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.3.0 This release

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page