Trust & Security

Encryption

In transit, at rest, and per-field — including tenant-specific keys.

Public HTTPS
Cloudflare
Origin connection
Deployment-specific
Field-level
AES-256-GCM, per-tenant keys

Cloudflare handles public HTTPS for the hosted sites. The connection from Cloudflare to the origin server is a separate configuration: a browser padlock confirms public HTTPS, not origin encryption or mutual authentication.

The production deployment target includes verified origin TLS and authenticated origin pulls. These controls must be checked for each deployed surface before being represented as active. The Webhook Lab currently uses Cloudflare public HTTPS with an HTTP origin connection. Ask your deployment operator for the configuration and evidence applicable to your own environment.

Field-level encryption

Fields marked secure are encrypted with AES-256-GCM using keys unique to each tenant. Decryption happens only at an explicit, authorized reveal. Encrypted values are structurally excluded from search indexes and AI processing — the exclusion is enforced by how values are stored, not by downstream filtering that could be forgotten.

Capability review: 2026-09-14. For exact current technical availability, use the generated API Map and first-class module inventory.