Hello Guillaume,
Any installation parameter entered when the app is installed is -
1. Encrypted before it is stored in our Database.
2. Only available to the same installed instance of the same App.
We have ensured that, by design, your sensitive data is only available to your own app users, and not to any other user on any other Freshdesk account.
Please do let us know if you would like more clarity here.
Thanks.
One more point - Installation parameters are also stored only in the same data center as the account is.
As a best practise all sensitive data should only be entered via installation parameters and not hardcoded inside the custom app.