Security controls · C0140
Is sensitive data encrypted in the pilot?
In the pilot (v0.2.0, synthetic data)
Short answer
Field-level AES-GCM protects Social Security numbers, MFA secrets and registration change history under a secret held by the hosting platform. Rotation, per-tenant keys and a key service are not in place.
This exists in the synthetic-data pilot only.
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Which algorithms does the production design use? Designed
- Are keys ever visible to administrators? Designed
See it in context: Encryption and key management · Search the help center · Ask a question