Keep credentials in one place, and label each sensitive field once.
A control layer holds two things you would rather it did not leak: the credentials it uses to reach your systems, and the sensitive values passing through it on the way to a decision.
Built into the Swiftward service you run.
Secrets stay out of the rules
Keys for the models, detectors and score vendors that a rule calls are held in one place, and only the part of the system that makes the call reads them. A rule never contains a model credential and cannot name one.
Stored secrets are encrypted at rest with AES-256-GCM, and each one is bound to its own field, so a value copied into another column cannot be decrypted. You can rotate a key without re-encrypting what is already stored. Or keep the keys in an external vault you already run.
Classification travels with the field
Declare a field sensitive once, and that setting decides how the field is treated everywhere it appears: on an operator's screen, in what is written to the record, in an export, in a forwarded event.
The alternative is remembering to hide a column on every screen that shows it, which fails the first time someone adds a screen.
Different from redaction
Classification is about a field you own and store. Redaction is about a value on its way to a model or back from a tool.