ENCRYPTED_SENTINEL: "[!ENCRYPTED$]" = '[!ENCRYPTED$]'

Sentinel value returned to API clients when an encrypted field's value cannot be disclosed (AllowDecryptInAPI=false and SendEncryptedValue=false). This allows clients to distinguish between null/empty values and protected values.