Field-level encryption
Sensitive columns — integration credentials, contact details, electronic signatures, device identifiers and audit-trail IP addresses — are encrypted with AES-256-GCM using a key held separately from the application secret, so rotating one does not compromise the other.