Encryption at Rest
How LucentSkill protects sensitive member PII and survey answers at the database layer with transparent AES-256-GCM encryption.
What it is
Sensitive columns are encrypted before they are written to the database and decrypted only server-side when read, so a database leak does not expose readable PII or survey free-text. Encryption is transparent: the rest of the application keeps working with plain values as before.
Encrypted columns cover survey responses' free-text answers, member name and email, the organization's primary contact name, email, and phone, the roster entry email, and the course-share recipient email. Member email, primary-contact email, roster email, and share recipient email use deterministic encryption so equality lookup still works (login, dedup, SSO mapping, and roster linkage are unaffected); names, phone, and survey answers use randomized encryption. The authentication audit log's email column is intentionally left as plaintext so it stays searchable from the audit viewer instead of being encrypted at rest (see Authentication Audit Log).
Use
- No action is required. Encryption happens automatically on every write and every read for covered columns, for existing data and new data alike.
Setup
The platform requires a dedicated DATA_ENC_SECRET environment variable (32 random bytes, base64) set in the production (Vercel) environment. It is distinct from the session JWT secret and the LLM-key encryption secret. If it is missing, encryption fails closed.
Security
- Encryption uses AES-256-GCM, authenticated with a per-value tag. Randomized fields use a fresh nonce per write; searchable email fields use a deterministic, column-bound key with an HMAC-derived nonce, never ECB and never a static nonce.
- Every ciphertext is versioned with an enc:v1 prefix so a future key rotation is detectable, and a wrong key fails closed instead of silently mis-decrypting.
- Partial or LIKE search is not possible on encrypted fields. The one derived lookup that needed it, resolving an email domain to its organization, uses a one-way HMAC blind-index column instead of scanning plaintext.
- The encryption secret and plaintext are never logged, and a backfill of existing data writes a local plaintext backup (kept out of source control) so the migration is reversible.