[{"data":1,"prerenderedAt":618},["ShallowReactive",2],{"navigation":3,"/security/encryption":258,"/security/encryption-surround":613},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":251,"api":260,"body":261,"description":607,"extension":608,"links":260,"meta":609,"navigation":610,"path":252,"seo":611,"stem":253,"__hash__":612},"docs/8.security/1.encryption.md",null,{"type":262,"value":263,"toc":591},"minimark",[264,268,273,276,348,353,365,377,385,389,396,400,449,453,460,473,477,480,483,487,491,501,534,538,544,584],[265,266,267],"p",{},"CredenShare uses industry-standard encryption to protect every credential you share. This page details the encryption mechanisms and security architecture.",[269,270,272],"h2",{"id":271},"where-encryption-happens","Where encryption happens",[265,274,275],{},"This depends on where the share is created, and the difference matters: on one path we hold a\nkey that could decrypt your content, and on the other we do not.",[277,278,279,295],"table",{},[280,281,282],"thead",{},[283,284,285,289,292],"tr",{},[286,287,288],"th",{},"Created via",[286,290,291],{},"Encrypted where",[286,293,294],{},"Can CredenShare decrypt it?",[296,297,298,310,324,337],"tbody",{},[283,299,300,304,307],{},[301,302,303],"td",{},"Web app",[301,305,306],{},"In your browser",[301,308,309],{},"No — the key never reaches us",[283,311,312,318,321],{},[301,313,314],{},[315,316,317],"a",{"href":133},"REST API",[301,319,320],{},"In your client",[301,322,323],{},"No — the API refuses plaintext",[283,325,326,331,334],{},[301,327,328],{},[315,329,330],{"href":221},"Official SDKs",[301,332,333],{},"In your process",[301,335,336],{},"No — the client encrypts before the request",[283,338,339,342,345],{},[301,340,341],{},"Slack app",[301,343,344],{},"On our servers",[301,346,347],{},"Yes — the credential passes through Slack first",[349,350,352],"h3",{"id":351},"web-and-api-shares","Web and API shares",[265,354,355,356,360,361,364],{},"A content key is generated in the client and used to encrypt your fields with ",[357,358,359],"strong",{},"AES-256-GCM","\nbefore anything is sent. That key travels in the share link's URL ",[357,362,363],{},"fragment",", which browsers\nnever transmit to a server. What we store is ciphertext plus a hash of an access token, so we\ncan serve the share to whoever holds the link without being able to read it.",[265,366,367,368,372,373,376],{},"The API enforces this rather than merely encouraging it: a create must declare\n",[369,370,371],"code",{},"e2ee-aes256-gcm"," and supply ciphertext, and a plaintext value is rejected. See\n",[315,374,375],{"href":165},"client-side encryption"," for the exact wire format.",[378,379,382],"callout",{"color":380,"icon":381},"info","i-lucide-key",[265,383,384],{},"Every share gets its own content key, so exposing one link cannot decrypt any other share.\nThe consequence is that losing the link loses the content — nobody, including us, can\nrecover it.",[349,386,388],{"id":387},"slack-shares","Slack shares",[265,390,391,392,395],{},"A credential sent through the Slack app has already passed through Slack before it reaches\nus, so client-side encryption buys nothing. These are encrypted ",[357,393,394],{},"on our servers"," with\nAES-256 envelope encryption, using a customer-managed key in AWS KMS. We can decrypt them; we\nsay so plainly rather than implying otherwise.",[269,397,399],{"id":398},"encryption-at-rest","Encryption at rest",[277,401,402,415],{},[280,403,404],{},[283,405,406,409,412],{},[286,407,408],{},"Component",[286,410,411],{},"Algorithm",[286,413,414],{},"Key management",[296,416,417,427,438],{},[283,418,419,422,424],{},[301,420,421],{},"Client-encrypted content",[301,423,359],{},[301,425,426],{},"Key held only by the link holder",[283,428,429,432,435],{},[301,430,431],{},"Server-encrypted content",[301,433,434],{},"AES-256 envelope encryption",[301,436,437],{},"Customer-managed key in AWS KMS",[283,439,440,443,446],{},[301,441,442],{},"Database fields",[301,444,445],{},"AES-256",[301,447,448],{},"Managed database encryption",[269,450,452],{"id":451},"encryption-in-transit","Encryption in Transit",[265,454,455,456,459],{},"All connections to CredenShare use ",[357,457,458],{},"TLS 1.2+",":",[461,462,463,467,470],"ul",{},[464,465,466],"li",{},"API endpoints: HTTPS required (HTTP redirected)",[464,468,469],{},"Web application: HSTS enabled",[464,471,472],{},"Internal calls: our functions authenticate to AWS services with scoped IAM roles",[269,474,476],{"id":475},"key-management","Key Management",[265,478,479],{},"For shares created from the web, the REST API or an SDK there is no server-side key. The\ncontent key is generated in the client and never reaches us, so there is nothing for us to\nhold, rotate or hand over.",[265,481,482],{},"Server-encrypted (Slack) shares use envelope encryption: a new data key is generated for every\nencryption operation, and the master key that wraps it is customer-managed in AWS KMS.",[269,484,486],{"id":485},"data-lifecycle","Data Lifecycle",[349,488,490],{"id":489},"client-encrypted-shares-web-rest-api-and-sdks","Client-encrypted shares — web, REST API and SDKs",[492,493,498],"pre",{"className":494,"code":496,"language":497},[495],"language-text","Encrypt in client → Store ciphertext → Serve ciphertext → Decrypt in browser → Delete\n","text",[369,499,496],{"__ignoreMap":500},"",[502,503,504,510,516,522,528],"ol",{},[464,505,506,509],{},[357,507,508],{},"Encrypt",": the client generates a content key and encrypts the fields",[464,511,512,515],{},[357,513,514],{},"Store",": we store the ciphertext plus a hash of an access token",[464,517,518,521],{},[357,519,520],{},"Serve",": we return the ciphertext to whoever presents the link",[464,523,524,527],{},[357,525,526],{},"Decrypt",": the recipient's browser decrypts using the key in the URL fragment",[464,529,530,533],{},[357,531,532],{},"Delete",": at expiration the ciphertext is deleted",[349,535,537],{"id":536},"server-encrypted-slack-shares","Server-encrypted (Slack) shares",[492,539,542],{"className":540,"code":541,"language":497},[495],"Create → Encrypt → Store → Access → Decrypt → Display → Delete\n",[369,543,541],{"__ignoreMap":500},[502,545,546,552,557,562,568,573,579],{},[464,547,548,551],{},[357,549,550],{},"Create",": the credential arrives from the Slack dialog",[464,553,554,556],{},[357,555,508],{},": the server encrypts it with a per-share data key wrapped by KMS",[464,558,559,561],{},[357,560,514],{},": the encrypted credential is saved to the database",[464,563,564,567],{},[357,565,566],{},"Access",": the recipient visits the share URL",[464,569,570,572],{},[357,571,526],{},": the server asks KMS to unwrap the data key",[464,574,575,578],{},[357,576,577],{},"Display",": the plaintext credential is shown to the recipient",[464,580,581,583],{},[357,582,532],{},": once expired or consumed, the encrypted data is deleted",[378,585,588],{"color":586,"icon":587},"success","i-lucide-shield-check",[265,589,590],{},"Expired credential ciphertext is deleted from the live database within an hour. Database\nbackups roll off on their own retention schedule — 7 days in production.",{"title":500,"searchDepth":592,"depth":593,"links":594},1,2,[595,600,601,602,603],{"id":271,"depth":593,"text":272,"children":596},[597,599],{"id":351,"depth":598,"text":352},3,{"id":387,"depth":598,"text":388},{"id":398,"depth":593,"text":399},{"id":451,"depth":593,"text":452},{"id":475,"depth":593,"text":476},{"id":485,"depth":593,"text":486,"children":604},[605,606],{"id":489,"depth":598,"text":490},{"id":536,"depth":598,"text":537},"How CredenShare encrypts and protects your shared credentials.","md",{},true,{"title":251,"description":607},"4f8vNzIjfOWrsKBi_XQZ2Rv81UyBWJV8dYB8-k8sM1Y",[614,616],{"title":242,"path":243,"stem":244,"description":615,"children":-1},"The fixture every CredenShare client must reproduce — what it covers, how to run it, and what it deliberately does not test.",{"title":255,"path":256,"stem":257,"description":617,"children":-1},"What CredenShare's security controls actually are today — what is built, what is not, and what we can show you.",1788908851491]