Authenticated encryption at rest
Stored secrets use AES-256-GCM. Each value gets its own random initialisation vector, and the authentication tag means altered ciphertext fails to decrypt rather than silently returning nonsense.
AES-256-GCM · per-value IV · auth tag
What is encrypted
Salesforce credentials, the Circularo API token, storage keys, SMTP and email-provider keys, and two-factor secrets. None of them are readable in the database.
SF · Circularo · storage · SMTP · 2FA secrets
Secrets are masked on the way out
Reading a configuration back never returns the secret itself. The interface shows that a value is set, not what it is.
GET responses mask · edits preserve
Tenants are scoped, always
Every query is scoped to the tenant it belongs to. Templates, rules, connections and documents cannot be reached from another tenant.
customer-scoped queries throughout
Parameterised queries throughout
Values never reach the database as concatenated strings, which is what closes off SQL injection as a class rather than case by case.
parameterised SQL · no string-built queries
A key change is visible, not silent
If the encryption key ever changes, affected connections show a clear warning and ask you to re-enter the credential, rather than appearing to work and failing later.
connection shows "Token unreadable"