Security & Trust

API Integrations & Credential Vault

One encrypted vault for every third-party credential your stack depends on -- never plaintext, never scattered across config files.

What you get

  • ✓A single field-driven provider registry covers SEO APIs, infrastructure, payments, and outbound email out of the box
  • ✓Every credential is encrypted at rest with AES-256-GCM and masked down to its last 4 characters in the admin UI
  • ✓Older plaintext records are detected automatically and re-encrypted the next time they're saved -- no manual migration
  • ✓Saving or deleting a credential is gated by its own dedicated permission, separate from general admin access