SemantiqWall
PT EN
Sign in I'm a vendor

← Trust Center

Cryptography and Key Management

Version
1.0
Owner
Founder
Approved by
Murilo Martins (Founder) · 09/28/2026
Next review
2027-09-28 (annual or on significant change)
Scope
All cryptographic keys, secrets and certificates used to run SemantiqWall, and all data the platform stores or transmits.

1. Roles

The Founder is the key custodian: generates, stores, rotates, revokes and destroys every platform key, and approves any change to cryptographic settings. From the first hire, a second person may be named custodian for specific keys, recorded in the security register. Customers manage their own API keys (policy 11).

2. Approved algorithms

Only standard, well-reviewed algorithms from maintained libraries are used. No home-made cryptography.

Use Algorithm
Data in transit TLS 1.2 or 1.3 (Caddy automatic HTTPS, publicly trusted certificates via ACME)
Application encryption AES-256-CBC with HMAC-SHA256 (Laravel encrypter, keyed by APP_KEY)
Passwords bcrypt
API key storage SHA-256 of a 40-character random token, compared in constant time
Audit log integrity SHA-256 hash chain
Webhook verification HMAC-SHA256 (WhatsApp, when enabled)
GitHub App authentication RS256-signed JWT, 10-minute lifetime
Server access and deploy SSH with ed25519 keys

SHA-1 appears only inside TOTP (RFC 6238 HMAC-SHA1), as the standard requires for compatibility with authenticator apps.

3. Data in transit (in place)

4. Data at rest

Encrypted by the application today (verified in code):

Not encrypted today (disclosed):

Commitments:

Customer-managed encryption keys (BYOK) are not offered.

5. Key inventory

Key or secret Where it lives Rotation
APP_KEY (256-bit) server .env, restricted permissions On suspected compromise; otherwise reviewed yearly
Database password server .env On suspected compromise or staff change
Database owner password (migrations only; in rollout) /etc/semantiqwall/db-owner.env, owned by root, mode 0600 (folder 0700), outside the application folder, never in the application .env; read by the deploy script only while migrating On suspected compromise or staff change
Copy of .env taken before the database-roles rollout (holds the same secrets as .env at that time, including the database owner password) /root/semantiqwall.env.antes-papeis, owned by root, mode 0600; kept only as the rollback copy Deleted once the rollout is confirmed (owner: Founder, target 2026-10-31); rotated with the secrets it holds
TLS certificates Caddy storage on the server Automatic renewal before expiry (about every 60-90 days)
Deploy key (read-only, ed25519) server, root-only Yearly, or on compromise
Founder SSH keys Founder's devices Yearly, on device change or loss
GitHub App private key file outside the repository, path in config Yearly, or on compromise
Supplier API keys (Resend, AI provider, WhatsApp) server .env Yearly, or on compromise or staff change
Customer API keys SHA-256 hash in the database Customer decides; revocable at any time

Keys are generated with cryptographically secure generators (random_bytes, openssl rand, ssh-keygen, php artisan key:generate, ACME). Each key has one purpose. The inventory is kept current in the security register.

6. Rotation, revocation and destruction

7. Monitoring