Skip to main content

Secure File Encryption Library

Project description

securefilecrypt — Simple AES-GCM File Encryption

SecureFileCrypt is a Python utility for encrypting and decrypting files using AES-256-GCM with password-based key derivation (PBKDF2-HMAC-SHA256).
It is designed for ease of use while providing strong, modern encryption with authentication to ensure data confidentiality and integrity.

Features

  • AES-256 in Galois/Counter Mode (GCM) for authenticated encryption
  • Password-based key derivation using PBKDF2-HMAC-SHA256 with configurable iterations
  • Random salt and nonce generated for each encryption
  • Automatic salt length derived from password characteristics
  • Simple file-based workflow: encrypt and decrypt with one function call
  • Compatible across Python 3.6+ on Windows, Linux, and macOS

Security Design

  • Encryption algorithm: AES-256-GCM (confidentiality + authentication)
  • Key derivation: PBKDF2-HMAC-SHA256, 100,000 iterations
  • Salt: Random per file, length based on password contents
  • Nonce: 12 bytes random per encryption
  • Password requirements: At least 12 base36 characters (0-9a-z)

Installation

pip install securefilecrypt

Quick Start

Encrypt a file

from securefilecrypt import EncryptFile

status, message = EncryptFile("secret.txt", "secret.enc", "mypassword123abc")
if not status:
  print("Error:", message)
else:
  print("File encrypted successfully!")

Decrypt a file

from securefilecrypt import DecryptFile

status, message = DecryptFile("secret.enc", "secret_decrypted.txt", "mypassword123abc")
if not status:
  print("Error:", message)
else:
  print("File decrypted successfully!")

Command line tool

On the command line the library can be called with the following arguments:

Usage: sfcrypt <input_file> <output_file> (--encrypt|--decrypt) (--pw:<password>|--ev:<envvar>)

<input_filename>  : Input file for encryption or decryption

<output_filename> : Encrypted / decrypted file to produce

--encrypt           : Encryption mode

--decrypt           : Decryption mode

--pw:<password>   : Password for encryption/decription

--ev:<envvar>     : Get password for encryption / decryption from an environment variable

API Reference

EncryptData(input_file, password)

Encrypts input_file using AES-256-GCM with provided password. Returns:

  • `status' (bool): True if successful, False something went wrong
  • message (str): Error message in case of error, otherwise empty
  • data (bytes): Encrypted bytes

DecryptData(input_file, password)

Decrypts input_file using AES-256-GCM with provided password. Returns:

  • `status' (bool): True if successful, False something went wrong
  • message (str): Error message in case of error, otherwise empty
  • data (bytes): Decrypted bytes

EncryptFile(input_file, output_file, password)

Encrypts input_file into output_file using AES-256-GCM with provided password. Returns:

  • `status' (bool): True if successful, False something went wrong
  • message (str): Error message in case of error, otherwise empty

DecryptFile(input_file, output_file, password)

Decrypts input_file into output_file using AES-256-GCM with provided password. Returns:

  • `status' (bool): True if successful, False something went wrong
  • message (str): Error message in case of error, otherwise empty

Security Notes

  • Always use a strong password (long, random, mix of letters/numbers).
  • Store your password securely — if lost, data cannot be recovered.
  • PBKDF2 is secure, but for higher resistance to GPU cracking, consider upgrading to Argon2id in the future.

License

MIT License — do anything with it, but no warranty.

Changelog

See the full changelog here.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

securefilecrypt-0.1.5.tar.gz (6.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

securefilecrypt-0.1.5-py3-none-any.whl (7.2 kB view details)

Uploaded Python 3

File details

Details for the file securefilecrypt-0.1.5.tar.gz.

File metadata

  • Download URL: securefilecrypt-0.1.5.tar.gz
  • Upload date:
  • Size: 6.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.12.10

File hashes

Hashes for securefilecrypt-0.1.5.tar.gz
Algorithm Hash digest
SHA256 d5e74998b48dd5126753a073d9ae18eff08c00bcf59873b5318f90a2d8b4008d
MD5 cf8cca9e8aed443539dd2c472cc7d47a
BLAKE2b-256 618cb35eb2b4970b677579d493f11484a28b3fe0eb0ced361239e72532e81e4d

See more details on using hashes here.

File details

Details for the file securefilecrypt-0.1.5-py3-none-any.whl.

File metadata

File hashes

Hashes for securefilecrypt-0.1.5-py3-none-any.whl
Algorithm Hash digest
SHA256 6360a8452ced0e1bd3aa41f29330d6afaabbd2b38ef1c1aad72f9ddf72ae5157
MD5 d3c1f337a1e2d5fcc6a35d1024c6aa6f
BLAKE2b-256 f9fc06926d9de9ba6987390e3348d56279db48c8d7b9012d69183273897be3d3

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page