Explainer · encrypt / decrypt
Seal a secret through three tiers
A value is sealed under the tenant's DEK with a data-AAD, then the DEK is wrapped under the environment's KEK. Step through it — the console shows the exact call and encryption context.
The data-AAD { tenant, column, dek_ver } and the wrap-AAD { tenant, "dek-wrap", kek_kv } are derived from the row, never passed by hand.