Encryption in Devolutions Hub Business protects all sensitive configuration and entry data using keys that are owned and managed by your organization, not by Devolutions. By default, secrets stored in your hub are encrypted at rest, and features such as the Encryption service extend this model to SSO scenarios by decrypting your hub key during login while keeping private keys under your control.
Hub owners can rotate encryption keys and re-encrypt configuration files when required, and must safeguard the emergency kit and private key backups because they are the only way to recover access if keys are lost. In practice, many customers store their emergency kit and private key in a separate secure system, then schedule periodic validation to ensure they can still unlock Devolutions Hub Business in a disaster scenario.