







DuckDB v1.4 ships database encryption capabilities. In this blog post, we dive into the implementation details of the encryption, show how to use it and demonstrate its performance implications.
Architecture
Overview of Ente's end-to-end encrypted architecture—learn how your data is encrypted on-device, securely shared, and safely stored using cryptography.

Cryptomator - Free & Open-Source Cloud Storage Encryption
Cryptomator is an open-source encryption tool for secure cloud storage. Protect your privacy for free on Dropbox, Google Drive, OneDrive, and more.

Add OPFS support by dengkunli · Pull Request #1490 · duckdb/duckdb-wasm
This PR adds OPFS (Origin Private File System) support for duckdb-wasm. With OPFS support, we could persist the database in the browser 🔥 API To remain simple and intuitive, no new api is added, ju...
Encryption + Trust & Safety reading list (updated 2026-05-20)
Encrypted Spaces — Research preview
An architecture for collaborative applications where data is encrypted and operations are cryptographically verifiable.

FiloSottile/age
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
Permissioned Data Diary 1: To Encrypt or Not to Encrypt - Daniel's Leaflets
The first in a series of posts about major design decisions along the way to a permissioned data protocol for atproto.
DuckLake Architecture Deep Dive
DuckLake is a next generation data lakehouse and open table format. It is significantly simpler and faster than Apache Iceberg or Delta Lake because it uses a SQL database for storing the catalog and metadata. This post covers an architecture deep dive with a detailed Q&A section. DuckLake consists of 3 components: storage, catalog, and compute. Each can be scaled independently, hosted locally with ease, and deployed to the cloud for production. MotherDuck offers managed DuckLake lakehouses for additional simplicity and performance.

DuckDuckGo - Protection. Privacy. Peace of mind.
The Internet privacy company that empowers you to seamlessly take control of your personal information online, without any tradeoffs.

Build a Rust CLI Using Seahorse
In this tutorial, you will learn how to build a CLI that encrypts and decrypts text based on a specified cipher, using Rust and Seahorse.

Equivariance Encryption for Private LLM Inference — Davide Cifarelli
This article shows how we can leverage equivariant transformations to run LLM inference on encrypted data without losing model performance.
Enpass: Secure Passkey & Password Manager That Keeps Your Data On Your Cloud Storage
With Enpass, choose where your passwords and passkeys are secured and synced – on your personal or business clouds (or even offline). Not on our servers
any-llm platform: Cloud Vault and Usage Tracking for LLMs
any-llm managed platform adds end-to-end encrypted API key storage and usage tracking to the any-llm ecosystem. Keys are encrypted client-side, never visible to us, while you monitor token usage, costs, and budgets in one place. Supports OpenAI, Anthropic, Google, and more.

any-llm platform: Cloud Vault and Usage Tracking for LLMs
any-llm managed platform adds end-to-end encrypted API key storage and usage tracking to the any-llm ecosystem. Keys are encrypted client-side, never visible to us, while you monitor token usage, costs, and budgets in one place. Supports OpenAI, Anthropic, Google, and more.
