Secret Vault
How IMS keeps sensitive database and integration credentials behind the server-side API boundary and exposes only the runtime values needed by authorized components.
Purpose
IMS uses a central protected secret store for credentials that should not be distributed as reusable plaintext application configuration. Access to those values is mediated by IMS.Api and tied to the requesting user/session, workstation, company/module/resource and intended secret.
Company database passwords
The IMS Global Companies screen can register/change a company database password, but an existing saved password is not displayed back in the form. During new database provisioning, IMS Global uses the password supplied for the new database and, after successful creation/validation, stores the secret through IMS.Api.