
WonderPhi Vault Industrial -- Commercial License
Commercial-license edition of Vault. Encryption, code signing, cert lifecycle, secrets scanning at enterprise scale.
© CRI-ONE. All rights reserved. Patents issued and pending. Unauthorized reproduction of the underlying designs is prohibited.
Extended catalog & full narrative — WonderPhi Vault Industrial -- Commercial License
The extended dossier appended from the 2026-08-05 catalog snapshot. Prices in the body copy have been stripped; the live-store price on this page is the authoritative figure. Images have been omitted.
WonderPhi Vault for organizations — perpetual single-organization commercial license
Everything below is identical to the retail product. What's different: your license covers the entire buying organization (unlimited machines, VMs, containers, cloud instances) with no seat count, no annual renewal, no telemetry, no activation. Redistribution / SaaS / hosted-service exposure require a separate OEM arrangement.
Easy Setup — No Package Manager, No Account, No Cloud
Single Python file. Python 3.8+ standard library only — nothing to pip install. Run with:
python wpv-recipe.py
Sample plan files ship with the download and run out of the box. Pair with WonderPhi Compute to execute the generated plans in parallel.
WonderPhi Vault — 30 batch recipes for encryption & security operations
Thirty recipes for the daily cryptography-and-audit chores: GPG encrypt/decrypt at scale, AES-256 file wrapping, code signing, TLS certificate lifecycle, tamper-evident hash sidecars, PII scanning, secret-scrub audits. Point at a folder or a key ring, get a plan.
Why this exists
Every organization has a cryptography backlog: "we should sign our releases", "we should audit certs monthly", "we should scan for PII in the exports folder". None of it is complicated. All of it stays undone because doing 400 things by hand is nobody's favorite Tuesday.
These recipes wrap the tools gpg, openssl, signtool, certutil, and a handful of pure-Python audit routines into batch operations. Encrypt 500 files. Verify 2,000 signatures. Scan a whole export folder for credit-card numbers. Rotate every internal cert.
What it is, in plain English
Each recipe knows how to do one crypto or audit task — encrypt this folder, decrypt that one, verify these signatures, scan for PII, hash every file for tamper detection. You give it a target (folder, file list, key ring). It emits a plan-line per input. Compute runs them in parallel. Nothing leaves your machine.
How you use it — three steps
- Run the recipe file.
python wpv-recipe.pyin the folder that contains your input files, or wherever you want the plan written. - Point at the target. The recipe asks (or reads from a text file) what the input is — a folder, a list of hostnames, a CSV, whatever the recipe expects. It writes a plan file: one shell command per line.
- Hand the plan to Compute. Drop the generated
plan.wpc.txtinto the WonderPhi Compute inbox, and every command runs in parallel across your cores. Read the honest log when it's done.
Worked examples — three of the 30 recipes in this library
gpg-encrypt-folder — encrypt every file in a folder for a recipient
One plan-line per file. All 500 files encrypt at once. Output goes to a separate folder you specify.
python wpv-recipe.py gpg-encrypt --input ./exports --output ./encrypted --recipient alice@example.com # emitted plan: # gpg --output ./encrypted/report001.pdf.gpg --encrypt --recipient alice@example.com ./exports/report001.pdf # gpg --output ./encrypted/report002.pdf.gpg --encrypt --recipient alice@example.com ./exports/report002.pdf
sha256-sidecar — drop a tamper-evident hash next to every file
Emits one .sha256 sidecar per file. Verify later with sha256sum -c.
python wpv-recipe.py sha256-sidecar --input ./release-artifacts
scan-pii — audit a folder for social security numbers and credit cards
Pure Python, regex-based. One plan-line per file. Aggregated report at the end.
python wpv-recipe.py scan-pii --input ./exports --output pii-audit.tsv
Verified capabilities
Recipes work on any Windows or Linux machine with the underlying crypto tool installed:
- 30 operations covered: GPG (encrypt, decrypt, sign, verify, key-import, key-fingerprint), AES-256 file wrapping, code signing (signtool for .exe, jarsigner for .jar, openssl-dgst for arbitrary files), TLS cert operations (generate CSR, self-sign, verify chain, extract SANs, days-until-expiry), hashing (SHA-256/512/MD5 sidecars, hash-tree, checksums.txt), audit routines (PII scan, secret-scrub for API keys / bearer tokens, sensitive-permission audit).
- Parallel encryption of 500 files in ~4 seconds on a 16-core box.
- Every recipe is offline. No cloud, no key-management-service integration — you use your own local
gpgoropenssl.
Every claim is testable on your own machine using the sample plans in the download.
Under the hood — the honest technical picture
Every crypto recipe delegates to the real thing: gpg, openssl, signtool, certutil. The recipe never rolls its own cryptography — it drives tools that have decades of scrutiny behind them. Audit recipes (PII scan, secret-scrub) are pure Python and their entire source is readable in a single sitting.
- Never rolls its own crypto. Delegates to well-known tools. Auditable.
- No key material handling. Recipes don't ship keys, don't manage keys, don't touch keys — they just invoke
gpgoropensslwhich use your existing keyring. - Reversible by default. Encrypt recipes never delete the source; you always keep the plaintext until you're satisfied.
- PII / secret-scrub is pattern-based. Fast, deterministic, no ML, no cloud calls. Regex definitions are inspectable and tunable.
- Offline-first. Every recipe works on an air-gapped machine.
How it compares to the manual way
| Aspect | The typical alternative | This product |
|---|---|---|
| Cost per new crypto operation | Write a shell loop and hope you quoted paths correctly | Run one recipe with two flags |
| Key exposure | Passwords in shell history | Delegates to gpg/openssl which use your existing keyring |
| Auditability | "I think we encrypted those exports last Tuesday..." | Plan file is a timestamped artifact you can archive |
| PII scanning | Buy a SaaS scanner + upload your sensitive data to it | Local regex scan, results never leave your box |
What you need
- Windows / macOS / Linux workstation.
- The crypto tools each recipe wraps:
gpg(GnuPG),openssl, and (on Windows)signtool. All standard-issue. - Python 3.8+ to generate the plan. Standard library only.
- WonderPhi Compute to run the plan in parallel.
What's in the download
wpv-recipe.py— the recipe generator (Python 3.8+, standard library only)README.md— per-recipe reference for humansINDEX.md— alphabetical list of every recipe with a one-line descriptionsamples/— ready-to-run demo input files for every recipeLICENSE.txt— perpetual single-user license, personalized with your name and order number at delivery
Common questions
Q. Does it upload my files anywhere?
No. Every recipe is offline. The PII scanner runs entirely in Python locally. The GPG / OpenSSL calls happen on your machine. Nothing goes over the network.
Q. Does it manage my GPG keys?
No. It uses your existing GPG keyring (~/.gnupg/ or %APPDATA%\gnupg). If you already have a key, you're set. If not, run gpg --gen-key once and then use these recipes.
Q. Can I use it for cloud KMS (AWS KMS, Azure Key Vault, GCP KMS)?
Not directly — these recipes are for offline / on-prem crypto. Cloud KMS is a very different model (network round-trips per operation) and doesn't benefit from local parallelism the same way. Different product.
Q. What patterns does the PII scanner look for?
Social security numbers (US), credit-card numbers (Luhn-validated to reduce false positives), phone numbers (E.164), email addresses, and API-key shapes for the big cloud providers. Patterns live in the recipe file — you can inspect and add your own.
Glossary — every term used above, in plain English
- Recipe
- One of the ready-made plan-file templates in this library. Each recipe knows how to do one job across many inputs.
- Plan file (
*.wpc.txt) - A plain text file with one shell command per line that WonderPhi Compute reads and executes across every CPU core in parallel.
- WonderPhi Compute
- The parallel runtime this recipe library is designed for. Sold separately, or bundled in the Complete Bundle.
- Shell command
- Any line you'd normally type into a terminal / Command Prompt / PowerShell prompt.
- Standard library only
- The recipe uses only what ships with Python 3.8+ — no
pip install, no external packages. - Perpetual license
- Buy once, use forever. No renewals, no expiration, no update check.
- GPG / GnuPG
- GNU Privacy Guard — the standard open-source implementation of the OpenPGP standard for file encryption and signing.
- AES-256
- Advanced Encryption Standard, 256-bit key length. The current gold standard for symmetric file encryption.
- Sidecar file
- A small companion file next to a data file, holding metadata (like a SHA-256 hash) without touching the original.
- PII
- Personally Identifiable Information — anything that can identify a person (SSN, credit card, email, phone number).
- Code signing
- Cryptographically signing an executable so operating systems can verify who published it.
- Keyring
- Where your PGP keys live. Managed by
gpg.
License & support — Industrial variant
Perpetual, non-exclusive, non-transferable Industrial license. Covers all machines, VMs, containers, and cloud instances operated by a single organization (the legal entity named on the purchase receipt plus wholly-owned subsidiaries). No seat count, no machine limit, no renewals, no activation, no telemetry.
Employees, contractors, and consultants under the organization's direction may operate the software solely for the licensed organization's benefit. Rights end when their engagement ends.
Not permitted without a separate arrangement: redistributing the software; hosting it publicly; embedding it in a product/SaaS/PaaS you sell to third parties; sublicensing.
Support: email chris@cri-one.com.
Every download's LICENSE.txt is personalized at checkout with your organization name, order number, and issue date. USA sales.
ac3af5675d91bc7a379b4bef156e497b9097dfcb1964d89dcdc9b0a82489191aWonderPhi Vault Industrial -- Commercial License
Publicly online since 2010 · U.S. patent applications since 2012 · inventions offered since 2014. The work of Christopher Gabriel Brown, independently documented.

