Levi Durfee

Encryption as a Service, without the AWS/GCP setup

I built an encryption service. It's called rypt, and it's backed by GCP Cloud KMS.

A while back I wrote about envelope encryption. I still think it's important. But setting up a KMS, IAM roles, key rings, and audit logging just to encrypt some user data is a lot. Especially if you're one person or a small team. I wanted something where you sign up, get a key, and make a curl request.

So that's what rypt is. You send data over HTTPS, and you get ciphertext back. You can also use envelope mode, where you generate a DEK yourself and only send the DEK to rypt to wrap. Then your actual data never leaves your server.

Every operation gets logged. The log has the timestamp, key, key version, operation, result, request ID, and the caller's IP. You can export it. I think if you're going to trust someone with your keys, you should be able to see exactly what's being done with them.

There are four tiers:

The paid tiers include a monthly allowance, and then it's a small per-operation charge after that. I tried to keep it simple.

If you read my envelope encryption post, you already know GCP KMS is cheaper. A software key is $0.06 a month and an HSM key is $1.00 a month. That's not a secret. You're not paying rypt for the encryption. You're paying to skip the GCP project, IAM roles, key rings, service accounts, and building your own audit log. If you'd rather set all of that up yourself, you should. That's what I'd do too. But if you just want to encrypt some data and get on with your day, that's what rypt is for.

It's written in Rust and runs on Cloud Run. I want to be upfront that this is not zero-knowledge. Your plaintext briefly hits my API while it's being encrypted. It's held in buffers that get zeroed, and request bodies are never logged. But if that's not good enough for your data, use envelope mode. It's something I may pursue improving later.

It's been live for a couple days. I'm looking for people to test it and tell me what's broken or confusing.

Questions? Comments? Concerns? Send me an email.

#encryption #gcp #kms #rust #security