Encryption
An index and topic collection covering encryption services, key management systems (KMS), hardware security modules (HSM), envelope encryption, end-to-end encryption SDKs, certificate management, and code/data signing. This topic gathers the cryptographic primitives, managed services, and open-source libraries that protect data at rest and in transit across cloud, mobile, web, and supply-chain workloads. It includes managed KMS offerings (AWS KMS, Google Cloud KMS, Azure Key Vault), HSM and enterprise key management platforms, secrets and configuration encryption tooling (HashiCorp Vault, Doppler, SOPS), code- and artifact-signing infrastructure (Sigstore, Cosign, Notary, TUF), end-to-end encrypted messaging protocols (Signal, Matrix), and certificate authority APIs (Let's Encrypt, DigiCert, Amazon Private CA). Distinct from the broader Security topic, this collection focuses specifically on cryptography, keys, certificates, and signing.
Index entry only — little beyond a description and a link, and nothing machine-readable enough for an agent to act on without a human reading the site first.
API Evangelist profiles Encryption the way a machine reads it — 30 machine-readable artifacts, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Encryption scores 9.5/100 (minimal), with a separate agent-readiness read of 0/100 (human only). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance. Every facet and dimension name is a link: it opens that measurement's page on APIs.io, where the rating runs across the whole catalog — the exact checks that feed it, how every profiled provider distributes on it, and who is at the top of it.
Put this on your own site. The badge is drawn live from Encryption's current Kin Score — paste it once and it updates itself every time the score is recomputed. It follows your visitor's light or dark setting, and it links back here so anyone who sees it can read the full breakdown.
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/encryption/"
title="Encryption on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/encryption.svg"
alt="Encryption Kin Score — API readiness rating by API Evangelist" width="150" height="150" loading="lazy">
</a>
[](https://providers.apievangelist.com/providers/encryption/)
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/encryption/"
title="Encryption on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/encryption/card.svg"
alt="Encryption Kin Score — API readiness rating by API Evangelist" width="340" height="120" loading="lazy">
</a>
More shapes, themes and sizes → · Score as JSON · How badges work
How we profile Encryption
Each block below is one kind of artifact we hold for Encryption. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
Features 8
The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.
Notable capabilities this provider offers.
Managed Key Management Services
Cloud KMS offerings like AWS KMS, Google Cloud KMS, and Azure Key Vault provide managed creation, rotation, and lifecycle of cryptographic keys with hardware-backed protection a...
Hardware Security Module APIs
Network-attached HSMs and HSM-backed services such as AWS CloudHSM, Azure Dedicated HSM, and Google Cloud HSM expose tamper-resistant cryptographic operations through PKCS#11 an...
Envelope Encryption Patterns
Envelope encryption wraps data encryption keys (DEKs) with key encryption keys (KEKs) stored in a KMS, enabling scalable encryption of large data sets while centralizing key con...
End-to-End Encryption Protocols
Open protocols like Signal, Matrix Olm/Megolm, and MLS provide forward-secret, deniable end-to-end encryption for messaging, calling, and collaboration applications.
Certificate Lifecycle Automation
ACME-based services like Let's Encrypt, alongside enterprise CAs like DigiCert and Amazon Private CA, automate issuance, renewal, and revocation of TLS and code-signing certific...
Code and Artifact Signing
Sigstore, Cosign, Notary, and TUF provide keyless and key-based signing of container images, binaries, and software packages with transparency-log-backed verification.
Secrets and Configuration Encryption
Tools like HashiCorp Vault, Doppler, and SOPS encrypt secrets, environment variables, and configuration files in transit and at rest, integrating with KMS providers and CI/CD pi...
Open-Source Cryptographic Libraries
Libraries like Google Tink, libsodium, OpenSSL, and BoringSSL provide misuse-resistant primitives for symmetric, asymmetric, AEAD, hashing, and digital signature operations.
Scroll within the panel for all 8 ·
Semantic Vocabularies 1
JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.
JSON-LD contexts and semantic vocabularies used across these APIs.
Encryption Context
JSON-LDJSON Schema 2
Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.
Standalone JSON Schema definitions for this provider's data models.
CustomerMasterKey
JSON SCHEMAEncryptRequest
JSON SCHEMAJSON Structure 2
JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.
JSON Structure definitions describing this provider's data shapes.
Encryption Cmk Structure
JSON STRUCTUREEncryption Encrypt Request Structure
JSON STRUCTUREExamples 2
Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.
Example request and response payloads for these APIs.
Encryption Cmk Example
EXAMPLEUse Cases 7
What developers actually build with this provider — captured so the catalogue answers 'what is this for', not just 'what does this expose'.
What developers build with this provider.
Encrypting Data at Rest in the Cloud
Applications use cloud KMS APIs to encrypt database fields, S3 objects, and disk volumes with envelope encryption, ensuring keys never leave a managed boundary while data cipher...
TLS Termination and Certificate Renewal
Web platforms automate TLS certificate provisioning and rotation through ACME (Let's Encrypt) or enterprise CA APIs (DigiCert, Amazon Private CA), keeping in-transit encryption ...
Software Supply Chain Signing
Build pipelines sign container images and binaries with Sigstore/Cosign, anchoring artifacts to transparency logs so downstream consumers can verify provenance before deploying.
End-to-End Encrypted Messaging and Collaboration
Messaging applications integrate Signal protocol, Matrix Olm/Megolm, or MLS to provide forward-secret encryption where neither the service operator nor an attacker can read mess...
Secrets Management for CI/CD
HashiCorp Vault, Doppler, and SOPS encrypt secrets used across CI/CD pipelines, source control, and runtime environments, integrating with cloud KMS for sealed storage and audit...
Tokenization and Payment Cryptography
Payment processors and PCI workloads use services like AWS Payment Cryptography and Apple Pay tokenization to perform PIN translation, card encryption, and EMV operations under ...
Workload Identity and Zero-Trust Cryptography
SPIFFE/SPIRE issue short-lived, cryptographically verifiable workload identities (SVIDs) so services can mutually authenticate without long-lived secrets across multi-cloud envi...
Scroll within the panel for all 7 ·
Integrations 8
Pre-built integrations with other platforms tell you where this provider already fits in a stack.
Pre-built integrations with other platforms and tools.
AWS KMS
Managed key creation, envelope encryption, and HSM-backed cryptographic operations integrated across AWS services and accessible via SDK and REST APIs.
Google Cloud KMS
Multi-region, software- and HSM-backed key management for envelope encryption and signing across GCP services and external KMS scenarios.
Azure Key Vault
Centralized key, secret, and certificate management with HSM-backed key protection and tight integration into Azure services and Entra ID.
HashiCorp Vault
Open-source secrets management with a Transit engine for encryption-as-a-service, PKI engine for certificate issuance, and KMIP server for HSM integration.
Sigstore
Free, keyless software signing infrastructure built around Fulcio (CA), Rekor (transparency log), and Cosign (signing CLI), now broadly used for OSS supply chain integrity.
Let's Encrypt
Free, automated ACME-based certificate authority issuing billions of TLS certificates that underpin in-transit encryption for the public web.
Tink
Google's misuse-resistant cryptography library providing AEAD, MAC, hybrid encryption, and signature primitives with pluggable KMS backends.
Signal Protocol
Forward-secret, end-to-end encryption protocol used by Signal, WhatsApp, and others, providing double-ratchet key derivation and prekey-based async messaging.
Scroll within the panel for all 8 ·
Resources
Every other property we hold for Encryption — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 1
Portal, sign-up, and the first successful call
Build 1
SDKs, sample code, and the tooling you integrate with
← All providers · Data indexed from github.com/api-evangelist/encryption · machine-readable index on apis.io
This is an independent, third-party profile of Encryption, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.