No Per-User Pricing!

Scale your entire team without your software bill going up. Flat-rate means you pay one price, no matter how many users you add.

Back to Knowledge Base Security & Compliance

Data Encryption at Rest: Bank Details, Tokens & Secrets

Encryption at rest means sensitive data is unreadable in storage: vendor bank details, OAuth tokens, and 2FA secrets are AES-encrypted under independent key classes — so one compromised key exposes only what it protects.

Encryption in transit (TLS) protects data moving across networks; encryption at rest protects the same data sitting in a database — the breach scenario. This guide covers what's encrypted and why key separation matters. Part of the security model.

What gets encrypted — and why those fields

  • Vendor bank details — IBAN, SWIFT, account name and number: the payment destination, in the vendor master and on every request
  • OAuth integration tokens — the credentials connecting QuickBooks and Google: a leak here is a leak into your accounting system
  • 2FA secrets — the TOTP seeds; stored one-way where possible, and never recoverable in plaintext
  • Passwords — never encrypted, because they're never stored: one-way hashed, unreadable by design

Key separation: the layer most systems skip

Encrypting everything with one key is one breach from everything. The stronger architecture assigns independent key classes — bank details under one, tokens under another, 2FA secrets under a third — each on a versioned key ring (v1, v2…) supporting rotation without downtime. Compromise of one class exposes only that class; the others stay sealed. New data encrypts under the newest key; old records stay readable under the key that wrote them.

Frequently Asked Questions

What does encryption at rest protect against?

The database-breach scenario: an attacker or insider with storage access gets ciphertext, not bank details — while TLS handles the network leg.

How should encryption keys be managed?

Separated by data class, versioned for rotation, and held in server-side configuration away from the database itself — so a database compromise doesn't include its own keys.

Approvdit encrypts bank details, OAuth tokens, and 2FA secrets with AES under independent, versioned key classes. Book a live demo.