SSN encryption at rest
Every Social Security number is encrypted with AES-256-GCM before it touches the database. Keys live in GCP KMS in a separate key ring; the application service account holds encrypt/decrypt only — never key-management.
KMS keyring: afc-phi-keyring · key: ssn-encryption-key · 90-day rotation