Field-level encryption: choosing the layer that has to hold
Envelope encryption, the search and index problems it creates, and how to pick the encryption layer that matches your trust boundary.
Tag archive
Envelope encryption, the search and index problems it creates, and how to pick the encryption layer that matches your trust boundary.
Why rotation fails, the difference between replacing a key and versioning it, and a repeatable sequence with an overlap window.

Encrypting backups is now table stakes — a stolen or intercepted backup should be useless to whoever...
Una sola clave privada firma todos los tokens que emite nuestro servidor de autenticación, y a lo largo de su vida se ha mudado dos veces: nació dentro del proceso, fue desterrada a una bóveda de la que no puede salir y luego se reencarnó en un tipo de clave completamente distinto, más pequeño y más rápido. Cada mudanza ocurrió en un emisor en producción, con tokens en circulación.

Let's talk about managing Redis keys in your NestJS apps. Yeah, it's crucial for performance and...
One private key signs every token our auth server issues, and it has moved twice in its life: born inside the process, exiled to a vault it can't leave, then reincarnated as a smaller, faster kind of key entirely. Each move happened on a live issuer with tokens in flight. Here's what custody and algorithm changes actually take, and the quiet regression that rode in on a "more secure" commit.
Securing API keys and secrets for large language models (LLMs) is critical to prevent unauthorized access and data breaches. This article explores best practices, challenges, and alternatives for API key management.

The algorithms almost never break. Key custody, rotation, and crypto agility do, and 2026 has the receipts. Why a record that must outlast its own keys has to be designed for change from the first lin
Over the years, blockchain technology has unlocked key primitives that drive utility and adoption....

How to back up and recover SealedSecrets encryption keys in Kubernetes
I’m curious, at what point in your app do you encrypt data? Do you ever encrypt it explicitly? Or do...