Sylin.Koan.Classification 1.0.51

dotnet add package Sylin.Koan.Classification --version 1.0.51
                    
NuGet\Install-Package Sylin.Koan.Classification -Version 1.0.51
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Sylin.Koan.Classification" Version="1.0.51" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Sylin.Koan.Classification" Version="1.0.51" />
                    
Directory.Packages.props
<PackageReference Include="Sylin.Koan.Classification" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Sylin.Koan.Classification --version 1.0.51
                    
#r "nuget: Sylin.Koan.Classification, 1.0.51"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Sylin.Koan.Classification@1.0.51
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Sylin.Koan.Classification&version=1.0.51
                    
Install as a Cake Addin
#tool nuget:?package=Sylin.Koan.Classification&version=1.0.51
                    
Install as a Cake Tool

Sylin.Koan.Classification

Field-at-rest protection as Entity metadata: mark a writable string property and keep using ordinary Koan Data APIs.

Install

dotnet add package Sylin.Koan.Classification

Classification marks up Entity strings, so the Entity also needs a durable store — reference one Data connector and configure it (without one, Entity verbs fail with Koan Data has no provider candidates. Reference a Data connector and call AddKoan().):

dotnet add package Sylin.Koan.Data.Connector.Sqlite
"Koan": {
  "Data": {
    "Sources": {
      "Default": {
        "Adapter": "sqlite",
        "ConnectionString": "Data Source=app.db"
      }
    }
  }
}

Keep the ordinary Koan bootstrap — Data verbs work once the host is up:

using Koan.Core;   // AddKoan()

var builder = WebApplication.CreateBuilder(args);
builder.Services.AddKoan();

var app = builder.Build();
await app.RunAsync();

Meaningful use

Inside the running host — a request handler, a background service, or a console app started through services.StartKoan() — ordinary Entity verbs read and write; encryption rides the save:

using Koan.Data.Core.Model;               // Entity<T>
using Koan.Data.Abstractions.Annotations; // [Pii]
using Koan.Data.Core;                     // Save, Get

public sealed class Customer : Entity<Customer>
{
    [Pii] public string Email { get; set; } = "";
    public string DisplayName { get; set; } = "";
}

var customer = await new Customer
{
    Email = "ada@example.com",
    DisplayName = "Ada"
}.Save();

var loaded = await Customer.Get(customer.Id);

Email is stored in an authenticated AES-256-GCM envelope and materializes as plaintext through supported Entity reads. DisplayName is unchanged. Save() encrypts a persistence clone, so the caller's instance remains readable business data.

[Pii], [Phi], [Secret], and [Classified("category")] currently carry the same storage behavior. Categories describe meaning; they do not imply masking, search, tokenization, or different cryptography.

Local and production custody

The package supplies a local key provider automatically, so a bare reference works with no configuration. Keys persist in a keyring under the application's own .koan/keys/classification.json, which means protected values written today are still readable after a restart — the ordinary run-stop-run loop does not destroy them. Startup reports the exact keyring path.

Local custody is not production custody. The key sits beside the data it protects, is never rotated on a schedule, and inherits only the filesystem's protection. Koan warns about it outside Development and refuses it in Production unless Koan:AllowMagicInProduction is set. A real deployment registers its own IClassificationKeyProvider over whatever key service it already trusts, before AddKoan():

builder.Services.AddSingleton<IClassificationKeyProvider, ApplicationKeyProvider>();
builder.Services.AddKoan();

The provider owns durable custody and rotation retention. Koan owns scope derivation, envelope handling, encryption, and decryption. A missing key, damaged envelope, authentication failure, or unsupported classified property type fails loudly.

Automatic composition

  • Every supported Entity write path passes through one host-owned transform plan before provider I/O.
  • Every supported Entity materialization path reverses that plan before returning the Entity.
  • Classified Entity types are excluded from distributed Entity caching so decrypted objects do not become L2 values.
  • Active hard segmentation dimensions define the opaque key scope. Referencing Tenancy therefore partitions keys by tenant without a Classification-specific tenant accessor or configuration.
  • Startup reporting identifies AES-256-GCM, the selected key-provider type, compiled segmentation scope, and current exclusions.

Boundaries

  • Writable string properties only.
  • The guarantee applies to supported Koan Data/Entity paths. Calling a raw adapter or repository directly bypasses the Data facade and its transforms.
  • Existing plaintext values are tolerated on read for migration safety, but they are not backfilled automatically.
  • Ciphertext search, blind indexes, tokenization, caller-facing masking, message/log/vector redaction, backfill, and cryptographic erasure are not current capabilities.
  • The package is field-at-rest protection, not a complete privacy, compliance, or key-management system.

See TECHNICAL.md. Key-provider authors should reference Sylin.Koan.Classification.Contracts, not the functional package.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.51 112 9/13/2026
1.0.49 107 9/12/2026
1.0.47 95 9/12/2026
1.0.46 102 9/10/2026
1.0.43 106 9/10/2026
1.0.40 97 9/9/2026
1.0.37 103 9/9/2026
1.0.35 101 9/9/2026
1.0.31 103 9/9/2026
1.0.30 104 9/9/2026
1.0.26 100 9/5/2026
1.0.25 117 8/30/2026
1.0.24 102 8/30/2026
1.0.23 118 8/28/2026
1.0.22 99 8/28/2026
1.0.21 107 8/28/2026
1.0.20 93 8/28/2026
1.0.19 100 8/28/2026
1.0.18 113 8/27/2026
1.0.14 100 8/27/2026
Loading failed