Sylin.Koan.Classification
1.0.51
dotnet add package Sylin.Koan.Classification --version 1.0.51
NuGet\Install-Package Sylin.Koan.Classification -Version 1.0.51
<PackageReference Include="Sylin.Koan.Classification" Version="1.0.51" />
<PackageVersion Include="Sylin.Koan.Classification" Version="1.0.51" />
<PackageReference Include="Sylin.Koan.Classification" />
paket add Sylin.Koan.Classification --version 1.0.51
#r "nuget: Sylin.Koan.Classification, 1.0.51"
#:package Sylin.Koan.Classification@1.0.51
#addin nuget:?package=Sylin.Koan.Classification&version=1.0.51
#tool nuget:?package=Sylin.Koan.Classification&version=1.0.51
Sylin.Koan.Classification
Field-at-rest protection as Entity metadata: mark a writable string property and keep using ordinary Koan Data APIs.
Install
dotnet add package Sylin.Koan.Classification
Classification marks up Entity strings, so the Entity also needs a durable store — reference one Data
connector and configure it (without one, Entity verbs fail with Koan Data has no provider candidates. Reference a Data connector and call AddKoan().):
dotnet add package Sylin.Koan.Data.Connector.Sqlite
"Koan": {
"Data": {
"Sources": {
"Default": {
"Adapter": "sqlite",
"ConnectionString": "Data Source=app.db"
}
}
}
}
Keep the ordinary Koan bootstrap — Data verbs work once the host is up:
using Koan.Core; // AddKoan()
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddKoan();
var app = builder.Build();
await app.RunAsync();
Meaningful use
Inside the running host — a request handler, a background service, or a console app started through
services.StartKoan() — ordinary Entity verbs read and write; encryption rides the save:
using Koan.Data.Core.Model; // Entity<T>
using Koan.Data.Abstractions.Annotations; // [Pii]
using Koan.Data.Core; // Save, Get
public sealed class Customer : Entity<Customer>
{
[Pii] public string Email { get; set; } = "";
public string DisplayName { get; set; } = "";
}
var customer = await new Customer
{
Email = "ada@example.com",
DisplayName = "Ada"
}.Save();
var loaded = await Customer.Get(customer.Id);
Email is stored in an authenticated AES-256-GCM envelope and materializes as plaintext through supported Entity
reads. DisplayName is unchanged. Save() encrypts a persistence clone, so the caller's instance remains readable
business data.
[Pii], [Phi], [Secret], and [Classified("category")] currently carry the same storage behavior. Categories
describe meaning; they do not imply masking, search, tokenization, or different cryptography.
Local and production custody
The package supplies a local key provider automatically, so a bare reference works with no configuration. Keys
persist in a keyring under the application's own .koan/keys/classification.json, which means protected values
written today are still readable after a restart — the ordinary run-stop-run loop does not destroy them. Startup
reports the exact keyring path.
Local custody is not production custody. The key sits beside the data it protects, is never rotated on a schedule,
and inherits only the filesystem's protection. Koan warns about it outside Development and refuses it in Production
unless Koan:AllowMagicInProduction is set. A real deployment registers its own IClassificationKeyProvider over
whatever key service it already trusts, before AddKoan():
builder.Services.AddSingleton<IClassificationKeyProvider, ApplicationKeyProvider>();
builder.Services.AddKoan();
The provider owns durable custody and rotation retention. Koan owns scope derivation, envelope handling, encryption, and decryption. A missing key, damaged envelope, authentication failure, or unsupported classified property type fails loudly.
Automatic composition
- Every supported Entity write path passes through one host-owned transform plan before provider I/O.
- Every supported Entity materialization path reverses that plan before returning the Entity.
- Classified Entity types are excluded from distributed Entity caching so decrypted objects do not become L2 values.
- Active hard segmentation dimensions define the opaque key scope. Referencing Tenancy therefore partitions keys by tenant without a Classification-specific tenant accessor or configuration.
- Startup reporting identifies AES-256-GCM, the selected key-provider type, compiled segmentation scope, and current exclusions.
Boundaries
- Writable
stringproperties only. - The guarantee applies to supported Koan Data/Entity paths. Calling a raw adapter or repository directly bypasses the Data facade and its transforms.
- Existing plaintext values are tolerated on read for migration safety, but they are not backfilled automatically.
- Ciphertext search, blind indexes, tokenization, caller-facing masking, message/log/vector redaction, backfill, and cryptographic erasure are not current capabilities.
- The package is field-at-rest protection, not a complete privacy, compliance, or key-management system.
See TECHNICAL.md. Key-provider authors should reference
Sylin.Koan.Classification.Contracts, not the functional package.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Extensions.Configuration (>= 10.0.10)
- Microsoft.Extensions.Configuration.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Configuration.Binder (>= 10.0.10)
- Microsoft.Extensions.Configuration.EnvironmentVariables (>= 10.0.10)
- Microsoft.Extensions.Configuration.Json (>= 10.0.10)
- Microsoft.Extensions.DependencyInjection (>= 10.0.10)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Hosting (>= 10.0.10)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Logging (>= 10.0.10)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.10)
- Microsoft.Extensions.Logging.Console (>= 10.0.10)
- Microsoft.Extensions.Options (>= 10.0.10)
- Microsoft.Extensions.Options.ConfigurationExtensions (>= 10.0.10)
- Microsoft.Extensions.Options.DataAnnotations (>= 10.0.10)
- Newtonsoft.Json (>= 13.0.4)
- Sylin.Koan.Classification.Contracts (>= 1.0.12 && < 2.0.0)
- Sylin.Koan.Core (>= 1.0.39 && < 2.0.0)
- Sylin.Koan.Data.Abstractions (>= 1.0.41 && < 2.0.0)
- Sylin.Koan.Data.Core (>= 1.0.73 && < 2.0.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.0.51 | 112 | 9/13/2026 |
| 1.0.49 | 107 | 9/12/2026 |
| 1.0.47 | 95 | 9/12/2026 |
| 1.0.46 | 102 | 9/10/2026 |
| 1.0.43 | 106 | 9/10/2026 |
| 1.0.40 | 97 | 9/9/2026 |
| 1.0.37 | 103 | 9/9/2026 |
| 1.0.35 | 101 | 9/9/2026 |
| 1.0.31 | 103 | 9/9/2026 |
| 1.0.30 | 104 | 9/9/2026 |
| 1.0.26 | 100 | 9/5/2026 |
| 1.0.25 | 117 | 8/30/2026 |
| 1.0.24 | 102 | 8/30/2026 |
| 1.0.23 | 118 | 8/28/2026 |
| 1.0.22 | 99 | 8/28/2026 |
| 1.0.21 | 107 | 8/28/2026 |
| 1.0.20 | 93 | 8/28/2026 |
| 1.0.19 | 100 | 8/28/2026 |
| 1.0.18 | 113 | 8/27/2026 |
| 1.0.14 | 100 | 8/27/2026 |