How secure do you need to go? You could always roll your own encryption if you want to stay with the config file driven approach. That alone will keep the honest folk honest.
What's the problem with incorporating your
VB "modules" into your web based platform, exactly? Is it something you explored and shot down, or is there just no interest in a port?