A secure AES-GCM encryption utility with user-friendly features
Project description
secure-string-cipher
A simple, secure AES-256-GCM encryption tool with an interactive menu interface.
Developed for: Python 3.14
Backward compatible to: Python 3.10+
Features
- Encrypt and decrypt text and files with AES-256-GCM
- Inline passphrase generation – Type
/genat any password prompt to instantly generate a strong passphrase - Generate strong random passphrases with entropy calculation
- Store passphrases in an encrypted vault (optional)
- HMAC-SHA256 integrity verification to detect tampering
- Automatic backup creation (keeps last 5 backups)
- Atomic writes to prevent corruption
- Stream large files in chunks for low memory usage
- Text output in Base64 for easy copy/paste
- Clipboard integration available
Installation
Note: This project is developed for Python 3.14 (latest stable) and is backward compatible to Python 3.10+. We follow Python's official support policy and may drop support for older versions as they reach end-of-life.
# Recommended: install with pipx
pipx install secure-string-cipher
# Or with pip
pip install secure-string-cipher
# Or from source
git clone https://github.com/TheRedTower/secure-string-cipher.git
cd secure-string-cipher
pip install .
Usage
Run the interactive CLI:
cipher-start
You'll see this menu:
┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ AVAILABLE OPERATIONS ┃
┣━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┫
┃ ┃
┃ TEXT & FILE ENCRYPTION ┃
┃ ┃
┃ [1] Encrypt Text → Encrypt a message (base64 output) ┃
┃ [2] Decrypt Text → Decrypt an encrypted message ┃
┃ [3] Encrypt File → Encrypt a file (creates .enc) ┃
┃ [4] Decrypt File → Decrypt an encrypted file ┃
┃ ┃
┣━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┫
┃ PASSPHRASE VAULT (Optional) ┃
┃ ┃
┃ [5] Generate Passphrase → Create secure random password ┃
┃ [6] Store in Vault → Save passphrase securely ┃
┃ [7] Retrieve from Vault → Get stored passphrase ┃
┃ [8] List Vault Entries → View all stored labels ┃
┃ [9] Manage Vault → Update or delete entries ┃
┃ ┃
┣━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┫
┃ [0] Exit → Quit application ┃
┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛
Choose an option and follow the prompts.
Quick Passphrase Generation
When prompted for a password during encryption, you can type /gen (or /generate or /g) to instantly generate a strong passphrase:
Enter passphrase: /gen
🔑 Auto-Generating Secure Passphrase...
✅ Generated Passphrase:
8w@!-@_#M)wF,Qn(ms.Uv+3z
Entropy: 155.0 bits
💾 Store this passphrase in vault? (y/n) [n]: y
Enter a label for this passphrase: backup-2025
Enter master password to encrypt vault: ••••••••••••
✅ Passphrase 'backup-2025' stored in vault!
✅ Using this passphrase for current operation...
This feature:
- Generates alphanumeric passphrases with symbols (155+ bits entropy)
- Optionally stores the passphrase in your encrypted vault
- Skips confirmation since you already saw the generated password
- Works seamlessly without leaving the encryption flow
Docker
Use the pre-built image (Python 3.14-alpine based):
# Pull and run
docker pull ghcr.io/theredtower/secure-string-cipher:latest
docker run --rm -it ghcr.io/theredtower/secure-string-cipher:latest
# Or with Docker Compose
git clone https://github.com/TheRedTower/secure-string-cipher.git
cd secure-string-cipher
docker compose up -d
docker compose exec cipher cipher-start
To encrypt files in your current directory:
docker run --rm -it \
-v "$PWD:/data" \
ghcr.io/theredtower/secure-string-cipher:latest
With persistent vault and backups:
docker run --rm -it \
-v "$PWD/data:/data" \
-v "$PWD/vault:/vault" \
-v "$PWD/backups:/backups" \
ghcr.io/theredtower/secure-string-cipher:latest
Image details: ~65MB Alpine-based image, Python 3.14, runs as non-root user (UID 1000), network-isolated, includes HMAC integrity verification and automatic backups (last 5 kept).
Security
- Encryption: AES-256-GCM with authenticated encryption
- Key derivation: PBKDF2-HMAC-SHA256 (390,000 iterations)
- Passphrase vault: Encrypted with AES-256-GCM using your master password
- Vault integrity: HMAC-SHA256 verification detects file tampering
- Automatic backups: Last 5 vault backups saved in
~/.secure-cipher/backups/ - File permissions: Vault files are user-only (chmod 600)
- Password requirements: Minimum 12 characters with complexity checks
Development
Quick Start
# Clone and install with dev dependencies
git clone https://github.com/TheRedTower/secure-string-cipher.git
cd secure-string-cipher
pip install -e ".[dev]"
# Format code before committing
make format
# Run the full test suite
make ci
Available Commands
make format # Auto-format code with Ruff
make lint # Check formatting, types, and code quality
make test # Run test suite
make test-cov # Run tests with coverage report
make clean # Remove temporary files
make ci # Run complete CI pipeline locally
Tools
- Ruff – Fast linter and formatter (replaces Black, isort, flake8)
- mypy – Static type checking
- pytest – Testing framework with 150+ tests
Run make format before pushing, then make ci to verify everything passes.
License
MIT License. See LICENSE for details.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file secure_string_cipher-1.0.16.tar.gz.
File metadata
- Download URL: secure_string_cipher-1.0.16.tar.gz
- Upload date:
- Size: 73.8 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
46ea3252dbf18caded68999b01a6e27483305c5e4a374e1b691145c87fb3f4a7
|
|
| MD5 |
da5505218926144b84da2791f7c97ae5
|
|
| BLAKE2b-256 |
ec7a85def37145fc3acb1cfbefa833854e627bd3ceb4a1567fa57df964c46af7
|
Provenance
The following attestation bundles were made for secure_string_cipher-1.0.16.tar.gz:
Publisher:
release.yml on TheRedTower/secure-string-cipher
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
secure_string_cipher-1.0.16.tar.gz -
Subject digest:
46ea3252dbf18caded68999b01a6e27483305c5e4a374e1b691145c87fb3f4a7 - Sigstore transparency entry: 692736592
- Sigstore integration time:
-
Permalink:
TheRedTower/secure-string-cipher@499fbab000a7789a7060664596c6665000896c50 -
Branch / Tag:
refs/tags/v1.0.16 - Owner: https://github.com/TheRedTower
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@499fbab000a7789a7060664596c6665000896c50 -
Trigger Event:
push
-
Statement type:
File details
Details for the file secure_string_cipher-1.0.16-py3-none-any.whl.
File metadata
- Download URL: secure_string_cipher-1.0.16-py3-none-any.whl
- Upload date:
- Size: 35.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4cc70046fd65e4f69a7a76476449c48fb2883dd7861e4a468d22ee0fe950095b
|
|
| MD5 |
a406f32342f914f3c4f29a6a2c0174a7
|
|
| BLAKE2b-256 |
ac24a333057f4e6ca2951916a4394edb79049b62773e6b7044df00a3bea6f494
|
Provenance
The following attestation bundles were made for secure_string_cipher-1.0.16-py3-none-any.whl:
Publisher:
release.yml on TheRedTower/secure-string-cipher
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
secure_string_cipher-1.0.16-py3-none-any.whl -
Subject digest:
4cc70046fd65e4f69a7a76476449c48fb2883dd7861e4a468d22ee0fe950095b - Sigstore transparency entry: 692736661
- Sigstore integration time:
-
Permalink:
TheRedTower/secure-string-cipher@499fbab000a7789a7060664596c6665000896c50 -
Branch / Tag:
refs/tags/v1.0.16 - Owner: https://github.com/TheRedTower
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@499fbab000a7789a7060664596c6665000896c50 -
Trigger Event:
push
-
Statement type: