Registry packagePublic

@rawctx/sf-shield-encryption

Data-at-rest encryption with tenant secrets, encryption keys, and field-level encryption policies.

OSISchema 1.0Domain crmSource developer.salesforce.comOwner @pasar6987

Native (downloadable) · Latest 1.0.1 published Mar 4, 2026 · 3 datasets / 2 measures in the latest preview · Updated Mar 10, 2026

Snapshot

Registry facts before deep inspection

Format, origin, ownership, and release context surface first so the package can be qualified quickly.

Format

OSI

Latest release

1.0.1Published Mar 4, 2026

Origin

Native (downloadable)Managed directly in rawctx

Installability

DownloadableDirect rawctx snapshot download

Domain

crm

Owner

@pasar6987

Organization

Independent

Repository

Not linked

License

MIT

Visibility

Public

Tags

salesforcecrmshieldencryption

Schema preview

OSI 1.0

Model preview

Structure before documentation

Preview the package footprint first, then open the dedicated explorer if you need field-level inspection.

Models1
Datasets3
Measures2
Dimensions30
Relationships0
AI context1
models/sf-shield-encryption.osi.yamlAI context included
3 datasets2 measures30 dimensions0 relationships

README

Package narrative and examples

Use documentation after the package qualifies on source, preview, and installability.

@rawctx/sf-shield-encryption

Data-at-rest encryption with tenant secrets, encryption keys, and field-level encryption policies.

Overview

Count
Objects (Datasets)3
Dimensions30
Measures2
Relationships0

Objects

  • DataEncryptionKey — The DataEncryptionKey object is part of the Bring Your Own Key (BYOK) feature, which allows users to upload a data encryption key (DEK) using a public key generated by the Salesforce Shield Key Management Service (KMS). Customers create their own DEKs and upload them to Salesforce. Users access this entity via the API to list DEK keys for auditing purposes. They can also programmatically use this object to create the certificate and to upload key material.
  • Platform Encryption Event Type — Platform Encryption event contains information about tenant secret and derived encryption key usage.
  • TenantSecret — This object stores an encrypted organization-specific key fragment that’s used with the primary secret (KDF seed) to produce org-specific data encryption keys.

Install

rawctx snapshot-download @rawctx/sf-shield-encryption

Topology

Semantic graph

Use the graph last, once the package has already qualified on release state, preview, and documentation.

Semantic Graph

Datasets 0 / Measures 0 / Dimensions 0 / Relationships 0

Loading semantic graph...

PackageDatasetMeasureDimensionRelationship