How can we help you?

Vault Fields Guide

Vault Fields Guide

Vault Fields let your team store a customer's sensitive information — a router admin password, a policy number, an account recovery code — directly on their contact record, encrypted, and retrievable only by an agent who is authorized and verifies their identity with a one-time authenticator code. It's part of the Compliance Pro plan.

Subscription requirement: Vault Fields require the Compliance Pro plan. Contact your administrator to check your plan or request an upgrade.

---

What Are Vault Fields?

A Vault Field is a custom contact field marked to store its value encrypted instead of as plain text. Once a field is marked as a vault field:

  • Its value is encrypted before it's ever saved.
  • Only agents whose role is on that field's approved list can view or edit it — and only after entering a 6-digit code from their authenticator app.
  • The value is never shown automatically in the contact panel. An agent has to deliberately unlock it.
  • The value can never be read by your AI bot, used in a routing rule, or referenced by an automated workflow. It's built to be reachable by a human agent only, on purpose.

This is different from a regular custom field, which any agent with contact access can see immediately, and different from SecureForms, which passes sensitive data through to your own systems without Velaro storing it. Vault Fields are for information you need Velaro to hold onto and have an agent pull up again later.

---

Who Uses Vault Fields

IT and tech support companies — Storing a customer's router or account admin password so a support agent can log in remotely to fix an issue on a future call, without that password sitting in plain text anywhere.

Property management companies — Keeping a tenant's portal login or gate access code on file so a leasing agent can help a locked-out tenant without paging IT or resetting the credential every time.

E-commerce and retail — Holding a customer's account recovery answer or a manually-issued gift card/store credit code that a support agent needs to be able to look up and read back, but that shouldn't appear in a transcript, report export, or be visible to every agent who opens the contact.

Any business that needs a human agent to be able to retrieve a sensitive value later — but never wants it sitting in plain text, showing up in AI conversations, or driving automated logic — is a fit.

---

Turning On Vault Fields

1. Confirm your plan includes Compliance Pro. If it doesn't, contact your administrator or Velaro support to upgrade.

2. Go to Settings → Custom Fields.

3. Click Create Field (or edit an existing field).

4. Turn on Store as Encrypted (Vault).

5. Choose which agent roles are allowed to unlock this field. Only the roles you select will ever be able to view or edit the value — leaving this blank locks everyone out, including administrators, so choose carefully.

6. Save the field.

You can have up to a set number of vault fields per account (your administrator can see the current limit and usage in Settings). If you need more, contact your administrator.

---

Setting Up Your Authenticator (Agents)

Before any agent can unlock a vault field, they need to enroll an authenticator app one time:

1. Go to Profile → Security.

2. Find the Vault Authenticator section and click Set Up.

3. Scan the QR code with an authenticator app — Google Authenticator, Microsoft Authenticator, Authy, or any similar app works.

4. Enter the 6-digit code the app shows you to confirm enrollment.

Once enrolled, that agent can unlock any vault field their role is approved for, using a fresh 6-digit code each time.

---

Using a Vault Field Day to Day

1. Open a contact who has a vault field on their record. It appears locked, with a padlock icon — the value itself is never shown.

2. Click Unlock.

3. Enter the current 6-digit code from your authenticator app.

4. If your role is approved for that field and the code is correct, the value appears. It's only shown to you, in that moment — it isn't saved anywhere else on your screen and re-locks when you navigate away.

To set or update a vault field's value, unlock it the same way, then enter the new value and save.

If you're not on the approved list for a field, or you haven't set up your authenticator yet, you'll see a message explaining you don't have access rather than the Unlock option.

---

Security and Compliance

  • Vault field values are encrypted before they're stored, using industry-standard AES-256 encryption. The encryption key itself is kept in a dedicated secure key management system — never in application code, and never accessible to Velaro staff outside of that system.
  • Access is gated two ways at once: the agent's role must be on the field's approved list, AND the agent must enter a valid code from their personal authenticator app. Both checks happen every time, for every unlock.
  • Every unlock attempt — successful or denied — is permanently logged for your compliance records. This log can't be turned off or thinned out.
  • A vault field's value is structurally excluded from AI, routing rules, and automated workflows. It isn't a setting that could accidentally be left off — the value simply never enters the systems those features read from.
  • This is part of Velaro's ongoing SOC 2 compliance program.

---

Common Questions

Q: Can I make an existing custom field a vault field?

A: Yes. Edit the field in Settings → Custom Fields and turn on Store as Encrypted (Vault). Note that any values already saved in that field before you turn on Vault stay as they were — only new values entered after the switch is on are encrypted going forward. For fully sensitive data, we recommend creating a new vault field rather than converting one that may already hold plain-text history.

Q: What happens if I lose access to my authenticator app?

A: Contact your administrator, who can help re-enroll you. For security, there's no way to unlock a vault field without a valid authenticator code.

Q: Can an administrator see a vault field's value without unlocking it?

A: No. Administrators must be on the field's approved role list and unlock it the same way any other authorized agent does.

Q: Will a vault field's value ever show up in a transcript, report, or export?

A: No. Vault field values are never included in transcripts, exports, or reports — they only ever appear on-screen to an authorized, authenticated agent who deliberately unlocks them.

Q: How many vault fields can I create?

A: Your plan sets a limit (3 by default). Your administrator can see current usage in Settings → Custom Fields.

Share: Email

Was this article helpful?