**Use this when** a collection holds data that should be unreadable in the database itself — a government ID, an API token, a health note, anything a stolen backup or a curious DBA must not see in cleartext. Mark the field `encrypted: true` and KernelCMS encrypts it transparently: your code reads and writes plaintext, the storage column holds authenticated ciphertext.