Encryption and hashing
encrypt() generates a random salt per call, so ciphertext written by
releases before that change cannot be decrypted and must be re-encrypted (see
the CHANGELOG).
File storage
StorageService keeps files for one user under a named folder. The fs and
path modules are injected as adapters, and the Node modules satisfy them
as-is. It is also what StorageServiceApprovalStore and
LocalStorageCheckpointStore write through.