Overview
To perform Audits or Journeys on websites that require authentication, users must provide credentials (usernames and passwords) within the ObservePoint platform. ObservePoint maintains a rigorous security framework to ensure these credentials are encrypted, isolated, and inaccessible to unauthorized personnel.
Masked Inputs
ObservePoint Audits & Journeys support Actions that allow users to input usernames and passwords. The Masked Input type is a special action type that masks and encrypts anything a user writes to that field after saving the Audit for Journey.
Below are details surrounding ObservePoint's security policies with masked input fields.
Credential Encryption and Storage
ObservePoint utilizes a multi-tenant security architecture that ensures your data is isolated from other customers.
Unique Encryption Keys: Passwords for authenticated audits and journeys are encrypted using a unique key assigned specifically to each customer account.
Data at Rest: All credentials are stored in an encrypted state within our secure production databases.
No Clear-Text Access: ObservePoint does not store or transmit passwords in clear-text format at any point during the storage process.
User Interface (UI) and Database
UI Masking: Once a password is saved in the Audit or Journey setup, it is masked. It cannot be revealed or retrieved by any user through the interface.
Database Security: Credentials cannot be viewed in clear text within the database. Even for administrators with database access, the data remains in its encrypted, ciphertext form.
ObservePoint Personnel Access
Access to the production environment's backend systems is governed by strict internal controls. These measures ensure that credentials remain protected and are never visible to or retrievable by ObservePoint administrators or support personnel.
Conclusion
Data security is a fundamental component of the ObservePoint platform. By utilizing customer-unique encryption keys and maintaining a Zero-Visibility architecture, we ensure that your authenticated scan credentials remain strictly confidential.

