Field-level encryption for PII at rest. This is the Python twin of the sealed-fields npm package: identical wire format, identical API shape, shared cross-language test vectors. Data sealed by either implementation unseals in the other.
pip install sealed-fields
from sealed_fields import create_sealed_fields, generate_key
sf = create_sealed_fields(
namespaces={"PII": {"key": os.environ["SEALED_KEY_PII"]}},
blind_index_key=os.environ.get("SEALED_BLIND_INDEX_KEY"),
)
token = sf.seal("free-text note about a real person") # "v1:..."
sf.unseal(token) # plaintext
sf.blind_index("alice@example.com") # HMAC lookup tokenSee the repository README for the full design: key rotation without a flag day, key namespaces, blind index entropy rules, row helpers, legacy-format decoders, and the fail-closed default.