Metadata-Version: 2.4
Name: osivault
Version: 0.2.0
Summary: One Smarter's shared security core: encryption at rest, tamper-evident audit logs, crypto signing, tokens, and MFA adapters.
Author-email: "One Smarter Inc. Engineering" <security@onesmarter.com>
License-Expression: MIT
Project-URL: Homepage, https://github.com/OneSmarterInc/OSIVault
Project-URL: Documentation, https://github.com/OneSmarterInc/OSIVault#readme
Project-URL: Repository, https://github.com/OneSmarterInc/OSIVault.git
Project-URL: Issues, https://github.com/OneSmarterInc/OSIVault/issues
Keywords: django,security,audit-log,encryption,hmac,crypto-agility,post-quantum,hipaa,tamper-evident
Classifier: Development Status :: 3 - Alpha
Classifier: Framework :: Django
Classifier: Framework :: Django :: 4.2
Classifier: Framework :: Django :: 5.0
Classifier: Intended Audience :: Developers
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.12
Classifier: Topic :: Security
Classifier: Topic :: Security :: Cryptography
Classifier: Topic :: Software Development :: Libraries :: Python Modules
Requires-Python: >=3.12
Description-Content-Type: text/markdown
License-File: LICENSE
Requires-Dist: django>=4.2
Requires-Dist: cryptography>=42.0.0
Provides-Extra: dev
Requires-Dist: pytest>=8.0.0; extra == "dev"
Requires-Dist: pytest-django>=4.8.0; extra == "dev"
Requires-Dist: pytest-cov>=4.1.0; extra == "dev"
Requires-Dist: psycopg2-binary>=2.9.0; extra == "dev"
Requires-Dist: build>=1.0.0; extra == "dev"
Requires-Dist: twine>=5.0.0; extra == "dev"
Dynamic: license-file

# OSIVault

OSIVault is One Smarter's shared security core: a single versioned Python package that every One Smarter application imports for encryption at rest, tamper-evident audit trail integrity, cryptographic signing and verification, token issuance, and strong multi-factor authentication adapters. Extracted from proven primitives in Concorde and MeshKor alongside healthcare EDI security requirements, OSIVault provides a unified, crypto-agile interface designed to ensure that cryptographic algorithm upgrades occur centrally without requiring application code changes.

For full architectural details, module inventories, provenance, governance rules, and monthly audit rituals, please consult the [OSIVault Core Charter](docs/charter.md).

## Installation

```bash
pip install osivault
```

## Module Surface

- `osivault.fields`: Field-level encryption at rest (AES-256-GCM) and blind-index search hashing.
- `osivault.audit`: Keyed, chained, tamper-evident audit records with database immutability guards.
- `osivault.sign`: Self-describing signatures over arbitrary bytes with post-quantum readiness.
- `osivault.tokens`: Session and service tokens with published verification keys.
- `osivault.auth`: Multi-factor authentication adapters (TOTP and WebAuthn/FIDO2 hardware keys).
- `osivault.watch`: Machine-readable algorithm inventory and compliance reporting.
