ArchitectureA supervised JVM-class runtime — OLTP on seven engines, OLAP on three. AI-native, MCP-native, observable as plain SQL.Read the architecture
Está viendo la edición Perú. Está viendo la edición Colombia. You're viewing the Pakistan edition. Cambiar a la edición global →Cambiar a la edición global →Switch to the global edition →

Secrets at rest: AES-GCM, a prefix-aware verifier, and a guard against scripts

Stored secrets move to an authenticated AES-GCM cipher with salt. Password verification reads the algorithm from the hash prefix, server passwords are encrypted at rest, and a script context cannot read a plain password.

A platform that connects to other systems holds their credentials. How it holds them is a question every security review asks. This release changes the answer on three fronts.

Encryption

  • AES-GCM with salt A new authenticated cipher for secrets at rest, with the previous CBC cipher kept under a versioned name for reading what it wrote. A test suite of some 600 lines covers the new one.
  • Database-server passwords encrypted Server, SMTP and JMX passwords are stored encrypted; a value loaded from an older configuration is detected as plain and treated accordingly, and the previous value is kept in a backup column populated only once.

Verification and containment

  • A verifier that reads the prefix Password verification selects the algorithm from the stored hash's prefix, so nothing in the platform handles a plain password in order to compare it.
  • Scripts cannot read a plain password The accessor checks its caller and refuses when invoked from a GraalVM scripting context. The secure wrapper rejects null or blank values and offers verification instead of exposure.

A later release moved user password hashing to Argon2id and rotated JWT keys. This release is about everything else the platform keeps on behalf of other systems.