Skip to content

Docs: explain what on-device encryption is for and where it stops - #550

Merged
simonhamp merged 1 commit into
mainfrom
docs/on-device-encryption
Oct 2, 2026
Merged

simonhamp merged 1 commit into
mainfrom
docs/on-device-encryption

Conversation

@simonhamp

Copy link
Copy Markdown
Member

Rewrites the second half of the mobile v4 security page.

The old text told developers they could "safely" encrypt data with Crypt and only mentioned the downside in a caution at the bottom. The new text leads with what on-device encryption is for and is direct about its limits.

What it now says:

  • Laravel's encrypter works out of the box because each device gets its own APP_KEY in the Keychain or Keystore. No plugin is needed.
  • The point is to stop someone who gets at the app's files or database from reading sensitive values. It suits short-lived tokens and anything that can be fetched again.
  • The key never leaves the device, but the app's data is backed up and restored. Data whose only copy is encrypted on the device can be lost for good, so long-lived data belongs somewhere else.
  • Apps should expect values they can no longer decrypt and handle DecryptException.
  • Encrypted values should not be sent to a back-end or third party, since they cannot be decrypted without the key.
  • Secure Storage is described as an alternative that keeps a value out of the database and files entirely. It is device-bound in the same way.

Things to check:

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@simonhamp
simonhamp marked this pull request as ready for review October 2, 2026 23:23
@simonhamp
simonhamp merged commit 30668cc into main Oct 2, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant