Coming soon

Developer library · .NET · C# and VB.NET

Bastion Archive Sdk

Forty archive formats. One managed assembly. Safe by default.

A fully managed .NET archive library. It reads more than forty archive, package, disk-image and file-system formats, writes the ones worth writing — ZIP, 7z, tar and the stream formats — takes no third-party runtime dependency, and extracts hostile archives safely by default.

40+

archive, package, disk-image and file-system formats read, each verified against the tool that owns it

18

target frameworks from .NET Framework 4.6 to .NET 10 — one assembly each, no native code

0

third-party runtime dependencies. Every codec is written in the library, from published specifications

2.2bn

fuzzing executions in the latest campaign — 8 defects found, none open

Extract safely. Create 7z. A dozen lines.

Every archive-level operation returns a result object rather than throwing. The same code reads naturally in C# and VB.NET, and every sample ships in both.

VB.NET

Imports Bastion.Archive

' Extract anything it reads - safely, by default.
Dim x = clsArchive.ExtractAll("upload.7z", "C:\Inbox", clsExtractionPolicy.Default)
If x.ErrorCode <> enmErrorCode.None Then
    Console.WriteLine(x.ToString())      ' refused, never thrown
    Return
End If

' A solid, encrypted 7z with 7-Zip's own level 9 settings.
Dim s = clsCompressionSettings.SevenZip(level:=9)
s.Solid = True
s.HeaderEncryption = True
s.Password = strPassword

Dim r = clsArchive.Create("backup.7z", "C:\Data\*", enmArchiveFormat.SevenZip, s)

C#

using Bastion.Archive;

// Extract anything it reads - safely, by default.
var x = clsArchive.ExtractAll("upload.7z", @"C:\Inbox", clsExtractionPolicy.Default);
if (x.ErrorCode != enmErrorCode.None)
{
    Console.WriteLine(x.ToString());     // refused, never thrown
    return;
}

// A solid, encrypted 7z with 7-Zip's own level 9 settings.
var s = clsCompressionSettings.SevenZip(level: 9);
s.Solid = true;
s.HeaderEncryption = true;
s.Password = password;

var r = clsArchive.Create("backup.7z", @"C:\Data\*", enmArchiveFormat.SevenZip, s);

Full API reference, format support and 44 worked recipes →

Why teams choose it

Every codec written here

Deflate, Deflate64, LZMA, LZMA2, BZip2, XZ, PPMd, Zstandard, the branch and delta filters, the checksums and the encryption are all implemented in the library. It never calls DeflateStream or System.Formats.Tar, so a runtime upgrade can never change its output.

Nothing throws into your code

Reading a broken archive somebody else made is an answer, not an accident. Every operation returns ErrorCode, ErrorDescription, Detail and Warnings — no Try block needed.

Safe with hostile input

Paths canonicalised, zip bombs and overlapping entries refused, limits enforced while the operation runs, checksums verified before data is exposed, links opt-in. On by default, not available on request.

Deterministic, and tested for it

The same input and settings give byte-identical output on every framework and operating system, serial or parallel — SHA-256-verifiable. Timestamps and ordering are settings, never ambient state.

Safe output

Fail-if-exists by default. Everything is written to a temporary neighbour, moved into place only when complete, then reopened and validated. Updating an archive is a rebuild, never an in-place mutation.

Bounded memory

Every read and write path streams. Memory is decoupled from archive size and entry count; there is no “load the whole archive” path anywhere.

Also in the box: a FileSystem abstraction where disk folders, memory folders and ZIP and 7z archives are all folders; an async twin for every long-running call with per-call cancellation; progress, password, overwrite and retry events; self-extracting archives for x64 and ARM64; split and spanned volume sets; and Mark-of-the-Web propagation, including out of nested archives.

Formats it reads

Every format below has been verified against the tool that owns it — 7-Zip, Info-ZIP, bsdtar, xz, zstd, makecab, DISM, qemu-img, WinRAR, WinZip, Windows Explorer and macOS Archive Utility among them. Nothing is listed on the strength of the specification alone. Anything it cannot read correctly is refused by name, never read approximately.

FamilyFormats
ArchivesZIP (zipx methods, WinZip AES, Zip64) · 7z (verified against six 7-Zip releases) · tar (ustar, GNU, pax, sparse) · RAR 5.0 (extract only) · CAB (not Quantum) · cpio · ar and .deb · RPM · xar · LHA/LZH · ARJ · NSIS installers
Compressed streamsgzip · bzip2 · XZ · LZMA · Zstandard · LZ4 · Brotli · Unix compress (.Z) · tar.gz, tar.bz2, tar.xz, tar.zst
Disk imagesISO 9660 with Joliet, Rock Ridge and El Torito · UDF 1.02–2.50 · WIM and ESD, including LZMS solid resources · VHD, including differencing · VHDX (fixed, dynamic) · VMDK · QCOW2, including LUKS-encrypted · VDI · DMG (every hdiutil compressor)
File systemsFAT12/16/32 · NTFS (not NTFS-compressed files) · ext2/3/4 · HFS+ and HFSX · APFS · SquashFS · cramfs · GPT and MBR partition maps
Executables and containersPE sections and resources · ELF · Mach-O, including universal binaries · UEFI firmware volumes · CHM · Compound File (OLE2, MSI) · Intel HEX · numeric split sets (.001) · self-extracting archives

Formats it writes

Far fewer, deliberately. Reading a format and writing it are separate pieces of work, and a format not listed here says so by name when asked to write it.

FormatCreateUpdateEncryptVolumesNotes
ZIPYesYesYesYesStore, Deflate, Deflate64, bzip2, LZMA, XZ, PPMd. Zip64. WinZip AES-128/192/256. Update rebuilds in one pass, untouched entries copied still compressed.
7zYesYesYesYesEvery coder and filter it reads: LZMA, LZMA2, PPMd, BZip2, Deflate and all branch filters. Solid blocks, compressed and encrypted headers, AES-256.
tar familyYesNo——ustar, GNU and pax, plus .tar.gz, .tar.bz2, .tar.xz and .tar.zst in one call.
gzip, bzip2, XZ, LZMAYes———Single streams, verified both ways against the reference tools.
ZstandardYes———Within 1% of the reference zstd at level 9, smaller at levels 1 and 5. 7-Zip cannot create a .zst at all.
WIMPartialNo—YesStored and XPRESS-compressed images that DISM lists and applies. 7-Zip’s own WIM writer only stores.
Self-extractingYes—YesYesA managed stub for x64 and ARM64: silent runs, passwords, overwrite handling and a custom icon.
RARNo———Never. The UnRAR licence forbids re-creating RAR compression, so no .NET library writes it.

Hostile archives, handled

The archive is hostile and the caller is trusted. Whatever it contains, an archive must never write outside its target directory, exhaust the machine, hand back bytes it did not have, or crash the process. The defaults are strict, and loosening one is a change somebody can find in code review.

SettingDefaultWhat it stops
AllowParentTraversal / AllowAbsolutePathsFalseZip-slip: .., C:\Windows, /etc and UNC paths in entry names
RejectReservedNames / RejectAlternateStreamsTrueCON, NUL, COM1 and file.txt:hidden on Windows
SymbolicLinks / HardLinksSkip, with a warningA link written first and followed by a later entry writing through it
RefuseOverlappingEntries / RefuseDuplicateEntriesTrueOne file that reads as two things, and names whose outcome depends on order
MaxCompressionRatio100,000Zip bombs — the Fifield class exceeds 28,000,000
MaxTotalBytes / MaxEntryCount / MaxNestingDepth1 TiB / 10 million / 256Archives that unpack to more than a disk holds, or whose listing is the attack
VerifyChecksums / OverwriteTrue / fail if it existsBytes that do not match, and archives replacing files already there

A security corpus that never regresses

Zip bombs, traversal in every shape three platforms allow, link escapes, overlapping entries and a 140,000-input mutation soak that insists on an error, never an exception.

Cross-tool verification

Reads what other tools wrote and hands what it wrote back to them. A reader and writer that share a misunderstanding agree perfectly and produce files nothing else opens — so both sides are gated externally.

Coverage-guided fuzzing

AFL++ over the whole read path. The campaign finished on 24 September 2026: 2.205 billion executions, 49 crashes, 8 defects, none open, and every one now a permanent test.

Performance, printed as measured

Against 7-Zip 26.03 (x64), both single-threaded, on the Silesia corpus. Where this library is faster it is said; where it is slower the figure is printed rather than omitted.

MeasureAgainst 7-ZipDetail
Deflate decode101%Faster than 7-Zip on seven of twelve files
Deflate encode75%29% to 174% across the corpus
LZMA2 decode58%Up to 140% on xml
LZMA2 encode29%The weakest figure on the page, and work in hand
LZMA2 compressed sizeWithin a few per cent13.8% smaller than 7-Zip on nci, 9.4% smaller on xml

Reading is where most archive work happens, and reading is competitive: Deflate — what the overwhelming majority of ZIP files use — decodes as fast as 7-Zip’s native code.

It fits where your application already runs

Frameworks.NET Framework 4.6 to 4.8.1 · .NET Core 2.0 to 3.1 · .NET 5 to .NET 10 — eighteen builds, no netstandard facade
PlatformsWindows, on every build — the same bytes out on every run, serial or parallel
LanguagesC# and VB.NET, with every sample in both
DependenciesNone third-party. Microsoft’s own polyfills only on the older targets that lack the API; none at all on .NET 6 and later
DeploymentOne DLL. Nothing native to ship, sign, or exclude from a trimmed or AOT build

How it compares

Capability and licensing matrix for commercial .NET archive libraries, from each vendor’s published documentation, surveyed September 2026. A ? means the capability was not stated either way — it is not a claim that the product lacks it.

Xceed Zip for .NETXceed Software
Bastion Archive SdkBastion Software Solutions
Aspose.ZIP for .NETAspose Pty Ltd
Formats
ZIP read and writeZip64, WinZip AES-256
✔
✔
✔
7z read and write
—
✔
✔
RAR read
—
✔RAR 5.0, extract only
✔
XZ and Zstandard
—
✔
✔
CAB, WIM and ISO
—
✔
✔partly
Disk images and file systemsVHD, VMDK, QCOW2, NTFS, ext, APFS
?
✔
?
Features
Split and spanned volumes
✔
✔
✔7z
Self-extracting archives
✔32-bit stub only
✔x64 and ARM64
✔
Non-seekable streaming
✔separate Real-Time Zip product
✔
?
Async API with cancellation
—
✔
—
Zip-bomb and overlap guard on by default
?
✔
?
Fully managed, no native code
✔
✔
✔
Licensing
Keep redistributing after updates lapse
—active subscription required
✔
✔
Server and SaaS deployment included
?
✔
✔OEM tiers only
LicensingPublished list price, 1 developer, perpetual with 12 months of updates, checked September 2026
$1,299.951 developer · Standardrenewal $960.35; redistribution only while subscribed
$6991 developer · OEM$3,49910 developers · OEM$6,999Unlimited developers · site
$2,3971 developer · Developer OEM$799 Small Business tier forbids redistribution
✔ supported— not offered? not stated in public documentation

Free libraries exist, and several are no longer maintained: SharpZipLib’s last release was January 2023, and DotNetZip is archived with an unpatched traversal CVE (CVE-2024-48510). Zip-slip remains the dominant vulnerability class in this category — which is why the guards above are on by default.

OEM licensing

One licence type, priced for commercial software teams. Every Bastion Archive Sdk licence is an OEM licence: build it into your product and ship that product to as many customers as you like, on as many machines as they like.

Developer OEM$6991 named developer
  • Royalty-free redistribution inside your own applications
  • Desktop, server, cloud and SaaS deployment — no per-server or per-instance fees
  • Perpetual licence with 12 months of updates; renewals at 35% of list
  • Every build, .NET Framework to .NET 10, and every sample in C# and VB.NET
Team OEM$3,499Up to 10 named developers
  • Everything in Developer OEM
  • $349 per developer
Site OEM$6,999Unlimited developers at one company
  • Everything in Developer OEM
  • No developer count to track as the team grows
  • Source-code escrow available, priced on request

Launch prices in US dollars. Final pricing is confirmed at release.

Try it properly first

A thirty-day evaluation of the complete component. Nothing removed and no limits — you evaluate exactly what you would buy.

Because the trial is the whole product, sales are final, and accepting the terms and conditions of sale is part of completing a purchase. The one exception: report a serious defect and, if we cannot fix it and release an update within thirty days, we refund you in full.

Need more than the component? Custom development and integration work built on it is available, remotely or on site — talk to us.

Get notified when Bastion Archive Sdk is released

Tell us what you are building. We will let you know the moment the evaluation is available — and answer plainly whether it fits.

Scroll to Top