> For the complete documentation index, see [llms.txt](https://enterprise.hideez.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://enterprise.hideez.com/hideez-enterprise-server/administration/data-protection.md).

# Data Protection

Hideez Enterprise Server – Data protection

{% hint style="info" %}
Data Protection ensures the secure storage of sensitive data in the database, such as device encryption keys, passwords, and OTP secrets.
{% endhint %}

### **Protected Data:**

* **Device Keys**: Encryption keys for Security Keys.
* **Passwords**: Including "Shared Account" passwords.
* **OTP Secrets**: Temporarily stored during transfer to devices.

### **How It Works**

Sensitive data fields in the database are encrypted using AES-256 encryption. The master encryption key is itself encrypted using a system-installed certificate. This key is decrypted at server startup, and all protected data is decrypted as needed.

### How to Configure Data Protection

1. Go to the **Dashboard** and click **Configure** in the Data Protection section, or navigate to **Settings → Data Protection**.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2F3rjMIqWQzFJhgjWL7Oh9%2FScreenshot_3.png?alt=media&amp;token=c5abdb22-3447-4404-b695-3f6b815c1101" alt="" width="563"><figcaption></figcaption></figure>

2. Enter a password for the certificate and download the certificate.\
   (If you don't have a certificate, you can create a self-signed one.)

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FrSvNHNEGvAIkATdk1vZ2%2FScreenshot_14.png?alt=media&amp;token=f115b2f8-0d6e-4f6d-b313-495d1d0b7efa" alt="" width="563"><figcaption></figcaption></figure>

3. Click **Enable Protection**.
4. Choose the downloaded certificate and enter the password from Step 2.
5. Check the boxes:
   * "I made a backup and I am aware of the potential risks"
   * "I have shut down all standby servers and will install the certificate as soon as they are restarted"
6. Click **Next** to complete the configuration.
7. Choose **Restart Now** or **Restart Later** to apply the changes.

<div><figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FTYrPmuxDKhYwh30HecC3%2FScreenshot_13.png?alt=media&amp;token=05e53277-8ed6-495e-b5f1-f0791562a361" alt=""><figcaption></figcaption></figure> <figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FjjI4DJhSixSDMEkOyEui%2FScreenshot_7.png?alt=media&amp;token=392604ba-22ac-47a9-b36e-05f2be6b5491" alt=""><figcaption></figcaption></figure> <figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FghMzWid1mUDinfzLf7Tp%2FScreenshot_8.png?alt=media&amp;token=813d5606-db32-4bac-a089-112bc2df5b0e" alt=""><figcaption></figcaption></figure></div>

**Now Data Protection is enabled.**

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2Fg7UlzgeauBRbGQuj5J2I%2FScreenshot_10.png?alt=media&amp;token=ab3ead13-ccad-448d-8def-0232d760593f" alt="" width="563"><figcaption></figcaption></figure>

You can also:

* **Change the Data Protection Certificate** or

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2Fati5Zh3jzqJ29BYUIgGV%2FScreenshot_11.png?alt=media&amp;token=cad7746e-0efd-496e-972d-20827b24f38a" alt="" width="279"><figcaption></figcaption></figure>

* **Disable Data Protection** when needed.

<figure><img src="https://1669663611-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FRdTysrljwe610dPFG7tE%2Fuploads%2FGRLpVdlZ3h5nNee4QsG5%2FScreenshot_12.png?alt=media&amp;token=cc601f0f-ccfe-4cc0-a939-c9d011cb915a" alt="" width="279"><figcaption></figcaption></figure>
