How we think about PII encryption in an Ionic + Angular app, to comply with the GDPR and the LOPD-GDD
Envelope encryption with a user-by-user key, what is encrypted and what isn't, how an external audit tested it, and the performance incident that led to our own security hardening. You built your AI app quickly: you ask the user for some data, call the model, save the result in the database, and you're in production. Comfortable, uncomplicated. Until one day you take a good look at what you're...
Cuentopia, a company that generates personalized stories for children using AI, has implemented a robust encryption system to protect sensitive data of minors. The system, designed in-house, uses envelope encryption with a master key stored in Google Cloud's Cloud KMS, and a user-specific key that encrypts sensitive fields before they are stored in the database.
The company worked with external auditors to test the system and made several security enhancements, including a performance adjustment to prevent a negative impact on user experience. The encryption system ensures that sensitive data, such as a child's profile and private story content, is protected, while public stories and catalog content are stored in plain text.
Written by urgent.news from Dev.to's report — not a translation of it. Machine-written — may contain errors; check the original before relying on it.