finds.dev← search

// the find

danielberkompas/cloak

★ 626 · Elixir · MIT · updated Aug 2026

Elixir encryption library designed for Ecto

Cloak is an Elixir library for encrypting data at rest, most commonly used to transparently encrypt Ecto fields via the companion `cloak_ecto` package. It's aimed at Elixir/Phoenix teams that need to store PII or other sensitive columns encrypted in Postgres/MySQL without hand-rolling IV management and key rotation.

Tagged ciphertext embeds the algorithm and key tag used to produce it, so decryption auto-selects the right key and key rotation doesn't require a side-channel migration flag to track which rows use which key. IVs are generated per-encryption with `:crypto.strong_rand_bytes` automatically, closing off the classic reused-IV mistake. It's a thin wrapper over Erlang's `crypto` library rather than a reimplementation of primitives, so it isn't carrying its own crypto bugs. The Vault behaviour lets you run multiple independently-configured vaults in one app, which matters for umbrella apps or per-tenant key separation.

The headline use case — encrypting Ecto fields — actually lives in a separate package (`cloak_ecto`), so this repo alone is only half the story and you'll need to pull in and version both. Cipher support out of the box is limited to AES-GCM and AES-CTR; anything else, including envelope encryption against a KMS or Vault, means writing your own `Cloak.Cipher` implementation from scratch. It's effectively a single-maintainer project going back to 2015 with modest adoption (626 stars) — a real bus-factor concern for a library protecting sensitive data long-term. Key management is entirely BYO: keys sit in Elixir config, with no built-in story for pulling them from AWS KMS, Vault, or similar secret stores.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →