Skip to content

Security Policy

k-msg provides a shared fieldCrypto policy layer for security-audit readiness.

This section covers encryption-at-write, hash-based lookup, key rotation, failure modes, and retention rules from an operator-focused perspective.

Question this page answers: In what order should non-security users read the fieldCrypto docs?

  • Default is secure; plaintext storage is denied by default.
  • failMode defaults to closed.
  • Lookups use HMAC-SHA256 hashes, not deterministic encryption.
  • Tenant early-deletion terms override legal baseline defaults.

Source of truth: