encryption

You Probably Don't Need Vault: How Deleting a Cache Made Our Key Storage More Secure
pCraft is a BYOK 'Postman for LLMs' whose database is full of other people's provider API keys, bearer credentials with a credit card behind them. This article walks through the envelope-encryption scheme that keeps a stolen database backup worthless, then tells the counterintuitive story of replacing HashiCorp Vault with a local key-encryption key: a change that deleted a plaintext-DEK cache a security review had flagged as critical and collapsed the key's in-memory lifetime from sixty seconds to microseconds. It covers AEAD binding contexts that defeat cross-tenant splicing, self-describing ciphertext, KEK rotation without re-encrypting rows, and how to tell when a managed secrets service is actually worth its operational cost.