Securing data with Make
Data security is important for operational integrity, confidentiality, and authentication.
You can use a variety of methods to secure your data in Make.
Methods and Make use cases
Select a method for more detailed information, including sample use cases with step-by-step instructions:
AES (Advanced Encryption Standard)AES (Advanced Encryption Standard)
AES is a symmetric algorithm that uses the same key for both encryption and decryption.
PGP (Pretty Good Privacy)PGP (Pretty Good Privacy)
PGP is a cryptographic tool that encrypts a message using both symmetric and asymmetric keys.
Digital signatureDigital signature
A digital signature is used to verify the identity of the sender and that a message or document is authentic and unaltered.
Hash functionsHash functions
Hash functions take variable-length inputs and produce fixed-length outputs of text that can't be reversed or decoded.
Methods of securing data overviewMethods of securing data overview
Learn how data security helps prevent data tampering and unauthorized access while minimizing data exposure.
Data security examples in Make
Consider the following examples to determine the best data security methods to use for your scenario.
Encrypt and decrypt data with a secret key that is not hidden
If you want to encrypt and decrypt data with a secret key that is not hidden (low data security):
Example:
An internal service to let teams search for non-confidential employee information without accessing the IdP (identity provider).
If a third-party manages to determine the webhook URL and API key, the secret key used for encryption and decryption protects the employee information. However, the key is not hidden in the scenario module.
Required resources:
- A module to connect to the IdP
- A secret key shared in advance with all the teams using the service
Encrypt and decrypt sensitive data with a hidden, secret key
If you want to encrypt and decrypt sensitive data with a hidden, secret key (more data security):
Example:
An internal service to give a limited number of users access to confidential employee information (for example: salary, home address, yearly reviews, etc.).
If a third-party manages to determine the webhook URL and API key, the secret key protects the employee information. Additionally, the shared AES key is encrypted by Make and is inaccessible.
Required resources:
- A module to connect to the IdP
- An AES key (128 or 256 bits) shared in advance with relevant users
Encrypt and decrypt sensitive data with a pair of private and public keys
If you want to encrypt and decrypt sensitive data with a pair of private and public keys (high data security):
Example:
A service to share confidential business information with a B2B partner.
PGP provides a high level of security against man-in-the-middle attacks. The sender and recipient exchange public keys in advance. The data is encrypted with the recipient's public key and signed with the sender's private key. The data is decrypted with the recipient's private key and the signature is verified with the sender's public key.
Required resources:
- A set of public and private PGP keys for the sender
- A set of public and private PGP keys for the recipient
Verify the sender and authenticity of a document
If you want to verify the sender and authenticity of a document:
Use a digital signature
Example:
A service to verify that the sender of a contract is legitimate and the contract has not been modified.
The sender creates a digital signature with a private RSA key and sends the contract to the recipient with the digital signature. The recipient uses the sender's public RSA key to verify the identity of the sender and that the contract has not been tampered with.
Required resources:
- A public and private RSA key for the sender. The public key is shared with the recipient in advance.
Secure and verify a password
If you want to secure and verify a password:
Use hash functions
Example:
A password system for a mission-critical application that requires additional security.
The password is never stored. Instead, the SHA-512 hash of the password is stored in a data store. Whenever a user logs in to access the system, the password they submit is hashed with SHA-512 and the hash is compared to the stored hash.
Required resources:
Create a secure audit log
If you want to create a secure audit log:
Use hash functions
Example:
A method to track users' actions in a system. The method prevents users from accessing or modifying the audit logs.
When a record of the userID and additional details are stored in the data store, a hash is stored as well. To access the record and verify that it has not been changed, your generated hash must match the stored hash. The random salt is saved in a different location, so no one can calculate a new hash if they attempt to modify the record.
Required resources: