Included from sgcWebSockets StandardAlso sold standalone
sgcCrypto — a Modern Cryptography Library for Delphi & C++ Builder
43 pure Object Pascal units, no components, no design-time footprint: pass TBytes in, get TBytes back. AES-GCM and ChaCha20-Poly1305 for encryption, SHA-3/BLAKE2/Argon2 for hashing, Ed25519/X25519/RSA for signatures and key exchange, X.509 certificate parsing and generation, and post-quantum ML-KEM, ML-DSA and SLH-DSA, whose keys and certificates go into the same X.509, PKCS#8 and PEM files as everything else. The pack also carries a TLS 1.3 and TLS 1.2 engine written in the same Object Pascal, selected with iohNativeTLS, with X25519MLKEM768 hybrid key exchange on by default. Every primitive is implemented directly in the unit you add to your uses clause: no external DLL, no OpenSSL binding, and the same source compiles unchanged from Delphi 7 through RAD Studio 13. sgcCrypto ships free with sgcWebSockets Standard, Professional and Enterprise, and is also sold standalone (bundling the sgcWebSockets Core runtime) for customers who only own Core.
3Post-quantum FIPS standardsML-KEM (203), ML-DSA (204), SLH-DSA (205)
2Ways to own itIncluded in an edition, or standalone
BEFORE YOU BUY
Three Things Worth Knowing First
What sgcCrypto is, whether you already own it, and where it runs. All three answers are short.
sgcCrypto is pure functions, not components
Every one of the 43 units exports plain functions and procedures. There is no Tsgc* class, nothing gets RegisterComponents'd, and there is no sgcCrypto_Reg.pas. You call sgcAES_GCM_Encrypt(aKey, aIV, aPlain, aAAD, aTag) the same way you would call any RTL function, from a form, a service, a console app or a thread.
Full source code ships with every license, so the primitives step through in your own debugger rather than disappearing into a binary or a DLL.
Edition overlap
Already own a sgcWebSockets edition?
sgcCrypto ships inside sgcWebSockets Standard, Professional and Enterprise, and inside All-Access, at no extra cost. If you already hold any edition license from Standard up, you already have all 43 units, nothing more to buy.
sgcCrypto exists standalone for the opposite case: you only own sgcWebSockets Core, or no sgcWebSockets license at all, and want the crypto units without licensing a full edition.
Platform scope
sgcCrypto carries no platform guard
Unlike the AI or speech packages, nothing in sgcVer.inc restricts sgcCrypto to Windows. The units are ordinary Object Pascal arithmetic, so they compile for Win32, Win64, Linux64, macOS, iOS and Android from the same source.
The one platform-aware unit, sgcCrypto_Random, selects a CSPRNG backend per target (BCryptGenRandom on Windows, or /dev/urandom elsewhere) behind the same sgcRandomBytes call, so your code never branches on platform.
WHAT IS IN THE BOX
43 Units, Six Capability Families
Every unit is compiled Object Pascal, callable from any Delphi 7 through 13 or C++ Builder project. There is no external DLL, no OpenSSL binding and no code generator: the primitives are implemented directly in the unit you add to your uses clause.
Symmetric5 units
AES, ChaCha20 and the AEAD constructions on top
sgcCrypto_AES covers CBC, GCM and CTR; sgcCrypto_Modes adds ECB, OFB, CFB, ciphertext-stealing CTS, AES-CCM, and AES Key Wrap / Key Wrap with Padding (RFC 3394 / 5649); sgcCrypto_CMAC is AES-CMAC and AES-GMAC. sgcCrypto_ChaCha implements ChaCha20, XChaCha20, Salsa20 and XSalsa20, and sgcCrypto_Poly1305 pairs Poly1305 with them into the ChaCha20-Poly1305 and XChaCha20-Poly1305 AEAD ciphers from RFC 8439. AES-CCM is the AEAD Zigbee, Bluetooth and the TLS CCM suites name, since it needs nothing beyond the block cipher itself, and CBC and ECB will both take the padding scheme of your choice, PKCS#7, ANSI X9.23, ISO 7816-4 and the rest, for the day you have to read what another system wrote. sgcAES_GCM_Decrypt and the Poly1305 verifiers compare the authentication tag in constant time and refuse to return plaintext when it fails.
sgcCrypto_SHA2 and sgcCrypto_Keccak cover SHA-1/2, SHA-3, SHAKE, cSHAKE and KMAC; sgcCrypto_Blake2b and sgcCrypto_Blake2s add BLAKE2. sgcCrypto_HMAC is keyed message authentication. For turning a password into a key: sgcCrypto_KDF (PBKDF2), sgcCrypto_HKDF, sgcCrypto_Scrypt and sgcCrypto_Argon2, which implements all three Argon2 variants, d, i and id, the Password Hashing Competition winner. sgcCrypto_SipHash gives you a fast keyed hash for hash-table keys, and sgcCrypto_TLSH is a fuzzy hash with a similarity-distance function, not a cryptographic digest, useful for near-duplicate detection.
Ed25519/Ed448, X25519/X448, secp256k1, Brainpool and RSA
sgcCrypto_Ed25519/Ed448 sign and verify; sgcCrypto_X25519/X448 do the matching Diffie-Hellman. sgcCrypto_ECCurves adds ECDSA and ECDH over seven curves, secp256k1, the three Brainpool curves and NIST P-256/P-384/P-521, with RFC 6979 deterministic nonces and signatures in the raw or the DER form, and BIP-340 Schnorr signing on top, with the x-only public keys Taproot, Nostr and Lightning expect. sgcCrypto_EC is the JOSE-oriented sibling: sign and verify a JWS directly, ES256/384/512. sgcCrypto_RSA verifies PKCS#1 v1.5 and PSS signatures straight from a PEM key, and sgcCrypto_RSA_Keys goes further with key generation at any bit length, OAEP and PKCS#1 v1.5 encryption, and DER/PEM export in both the PKCS#1 and the PKCS#8 BEGIN PRIVATE KEY form. RSA and EC keys import as readily as they export, DER or PEM, so a key generated once can be saved and loaded again instead of living only as long as the process. sgcCrypto_ECIES rounds it out with hybrid seal/open encryption to an X25519 public key.
sgcCrypto_ASN1 reads DER and PEM and parses PKCS#1/SEC 1 keys; sgcCrypto_DER writes every tag a certificate or CSR needs. sgcCrypto_X509 parses a certificate, verifies it was signed by a given issuer, walks and verifies a chain, verifies a CSR, and parses a CRL to check revocation. sgcCrypto_X509_Gen generates a self-signed certificate or a PKCS#10 CSR from scratch, and a CA issues with sgcX509_CreateSigned or sgcX509_CreateSignedFromCSR: full subject and issuer distinguished name, validity window, CA flag with a path-length constraint, key usage flags, extended key usage OIDs and subject alternative names, including IP address SANs, which now take IPv6 in any RFC 4291 text form, and URI SANs for SPIFFE-style service identities.
Signing is no longer limited to RSA and EC. sgcX509_MLDSAKey and sgcX509_SLHDSAKey wrap a post-quantum key for sgcX509_CreateSelfSignedEx and sgcX509_CreateCSREx, so a certificate or a CSR can be signed with ML-DSA or SLH-DSA. A CA can also certify an ML-KEM public key (RFC 9935), which cannot sign, so possession has to be proved some other way. On the reading side TsgcX509PublicKeyType gained x509pkMLDSA, x509pkSLHDSA and x509pkMLKEM, and sgcX509_VerifyChain now enforces the basicConstraints path length and the nameConstraints extension over dNSName, iPAddress, rfc822Name, uniformResourceIdentifier and directoryName, written on the generating side from PermittedDNSNames, ExcludedDNSNames, PermittedIPRanges and ExcludedIPRanges. An EC certificate still comes out roughly a third the size of an RSA one and verifies far faster, which is why new deployments reach for one.
ML-KEM, ML-DSA and SLH-DSA, plus a hybrid combiner
sgcCrypto_MLKEM is FIPS 203 key encapsulation, three parameter sets (ML-KEM-512/768/1024), with implicit rejection on a malformed ciphertext. sgcCrypto_MLDSA is FIPS 204 signing, ML-DSA-44/65/87. sgcCrypto_SLHDSA is FIPS 205, all six SHAKE parameter sets: 128s, 128f, 192s, 192f, 256s, 256f. Because ML-KEM alone bets everything on a lattice assumption younger than elliptic curves, sgcCrypto_MLKEM_Hybrid combines an X25519 secret and an ML-KEM secret into one shared key, so the result is never weaker than the classical half, the migration pattern the industry is converging on.
The same unit implements X-Wing (draft-connolly-cfrg-xwing-kem-10), X25519 with ML-KEM-768 as one KEM: a 1216-byte public key, a 32-byte private key (the seed), a 1120-byte ciphertext and a 32-byte shared secret, through sgcXWing_GenerateKeyPair, sgcXWing_Encapsulate and sgcXWing_Decapsulate. It also builds the TLS 1.3 hybrid key shares of RFC 10024 for X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024 (IANA codepoints 0x11EC, 0x11EB and 0x11ED). Those three are not standalone KEMs, they only build a TLS key share.
All three algorithms now read and write keys as X.509 SubjectPublicKeyInfo, PKCS#8 OneAsymmetricKey and PEM, so a post-quantum key lives in the same files as an RSA or EC one. ML-DSA and ML-KEM private keys have three forms, picked with TsgcPQCPrivateKeyFormat: pqkfSeed writes the seed alone (32 bytes for ML-DSA, the 64-byte d||z seed for ML-KEM), pqkfExpanded writes the expanded key, pqkfBoth carries both. SLH-DSA has a single private key form. sgcMLDSA_GenerateKeyPairAndSeed and sgcMLKEM_GenerateKeyPairAndSeed hand back the seed alongside the key pair, so a seed-form file can be written straight after generation.
One-time passwords, encoding, and encrypted ZIP entries
sgcCrypto_OTP generates and verifies HOTP and TOTP codes, the same six-digit codes an authenticator app shows, with a constant-time verification window that absorbs clock skew. sgcCrypto_Encoding holds the utility functions the rest of the library shares: constant-time compare, secure buffer zeroing, hex, Base64url and Base32. sgcCrypto_Zip_AE2 implements WinZip AES encryption, AE-1 and AE-2, for encrypting individual ZIP entries. sgcCrypto_Random is the cross-platform CSPRNG behind every key and nonce generated elsewhere in the library, and sgcCrypto_Legacy keeps MD4/MD5/HMAC-MD5/DES-ECB available for interoperability with older formats, not for new designs.
A TLS 1.3 and TLS 1.2 Engine in the Same Object Pascal
The pack also carries a TLS 1.3 and TLS 1.2 implementation written on top of the sgcCrypto primitives. It lives in the sgcSSL_NativeTLS* units rather than in sgcCrypto_*, so it is not one of the 43, and it ships wherever sgcCrypto does. Select it with one property on any sgcWebSockets client or server and there is nothing to deploy on any platform.
// Client: no OpenSSL, no SChannel, no platform TLS stack
WSClient.TLS := True;
WSClient.TLSOptions.IOHandler := iohNativeTLS;
// Lowest version allowed: tls1_2 negotiates TLS 1.3 or TLS 1.2, tls1_3 only TLS 1.3
WSClient.TLSOptions.Version := tls1_2;
WSClient.TLSOptions.RootCertFile := 'roots.pem';
// Optional: also trust the roots the operating system already trusts
WSClient.TLSOptions.NativeTLS_Options.UseSystemRoots := True;
// Both lists are OpenSSL style, colon separated. This group list is the default.
WSClient.TLSOptions.NativeTLS_Options.Groups :=
'X25519MLKEM768:X25519:secp256r1:secp384r1';
// Only TLS 1.3 suites here means TLS 1.3 only. Leave it empty for the default,// which adds the TLS 1.2 ECDHE suites with AES-GCM and ChaCha20-Poly1305.
WSClient.TLSOptions.NativeTLS_Options.CipherSuites :=
'TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256';
// Server: the same switch on SSLOptions, IOCP and EPOLL engines included
WSServer.SSLOptions.IOHandler := iohNativeTLS;
Post-quantum key exchange out of the box
The default group list starts with X25519MLKEM768, the RFC 10024 hybrid of X25519 and ML-KEM-768, so a handshake with a peer that supports it is already post-quantum with no configuration. SecP256r1MLKEM768 and SecP384r1MLKEM1024 are available on the same list.
Nothing to deploy, on any target
No libssl, no libcrypto, no SChannel and no platform TLS stack, just the same Object Pascal on Win32, Win64, Linux64, macOS, iOS and Android. Set TLSOptions.IOHandler := iohNativeTLS on a client, or SSLOptions.IOHandler := iohNativeTLS on a server, including the IOCP and EPOLL server engines.
The roots the machine already trusts
Set NativeTLS_Options.UseSystemRoots to True and the engine adds the operating system trust roots to RootCertFile: the ROOT store on Windows, and on every other platform the first CA bundle file found among the standard locations. It never reads the macOS or iOS keychain or the Android store. It is off by default, so the anchors stay exactly what RootCertFile says. On a server the same property applies to the client certificates it verifies.
Know the limits before you switch
The engine speaks TLS 1.3 and TLS 1.2 only, with no TLS 1.1, TLS 1.0 or SSL, and the hybrid post-quantum groups exist only in TLS 1.3, so a TLS 1.2 connection uses X25519, secp256r1 or secp384r1. There is no session resumption and no PSK, no 0-RTT and no QUIC. Revocation and certificate policies are not checked, and the component event OnSSLVerifyPeer is not available for it, the engine has its own verification hooks. Stay on OpenSSL or a platform backend when you need any of those.
QUICK START
No Component, No Object Inspector
Add a unit to uses and call a function. Every call below comes from a different one of the 43 units, spanning symmetric, hashing, signatures and post-quantum.
Tag checks, HOTP/TOTP verification and sgcConstantTimeEquals compare in constant time, and so does the work on the secret. AES runs on a bitsliced core that never indexes memory with a secret byte or branches on one, GHASH multiplies under a mask, and RSA private operations are blinded and checked against the public exponent before anything is returned. ECDSA signing, ECDH and EC key generation use a constant-time scalar multiplication, and Ed25519 signing reads the scalar in fixed windows with a complete addition formula.
Implicit rejection, and inputs checked first
A ciphertext of the right length that does not decrypt yields a pseudorandom secret instead of an error, implicit rejection per FIPS 203, so an attacker learns nothing from it. A public key that is malformed, a ciphertext or key of the wrong size, and a private key that fails the hash check are refused before any computation, and an imported ML-KEM, ML-DSA or SLH-DSA private key is checked for consistency, so a key whose parts do not belong together cannot be loaded by mistake.
Delphi 7 through 13, unchanged
No native 64-bit integer type is assumed. sgcCrypto_Int64 and TsgcBigInt emulate the arithmetic the hashes, curves and post-quantum units need, so the same source compiles on every supported version.
Nothing leaves your process
Every function runs in-process on data you pass in. There is no network call, no telemetry and no eSeGeCe relay anywhere in the library.
PRICING
Included, or a Standalone Pack
sgcCrypto ships free with sgcWebSockets Standard, Professional and Enterprise. If you only own sgcWebSockets Core, it is also sold as its own pack, starting at €149 for a single developer. All licenses include full source code, 1 year of updates and a 50% to 70% renewal discount: 50% when you renew one pack, 60% for two, 70% for three or more.
sgcCrypto
€149
Standalone pack. Single, Team and Site licenses available. Free if you already own sgcWebSockets Standard, Professional or Enterprise.
All 43 sgcCrypto_*.pas units
sgcWebSockets Core runtime included
Delphi & C++ Builder, all six platforms
Full source code
1 year of updates
Already on sgcWebSockets Standard, Professional or Enterprise? sgcCrypto is already in your installer, no order needed.
30-Day Money-Back GuaranteeNot satisfied? Request a full refund within 30 days of purchase. See refund policy
Cryptography Without the Component Overhead
43 pure functions covering encryption, hashing, signatures, PKI and post-quantum key exchange, plus a TLS 1.3 and TLS 1.2 engine built on them, ready wherever your Delphi or C++ Builder code already runs. Full source code, no relay, no DLL.