Field-level AES-256-GCM encryption/decryption library. Key Vault: RSA-OAEP wrap of per-message DEK. HMAC-SHA256 blind index for searchable fields. Config via environment (KeyVaultUri, KeyName, ManagedIdentityClientId, HmacSecretKey when using Key Vault).