The documentation says:
###Paypage Request Submission
All merchants receive a unique url to post their request to with a different domain for Sandbox, UAT and Production environments.
The unique url is derived from the AlphaHPP id that is generated when a paypage is created.
This is an example of how an URL might be configured for the AlphaHub sandbox:
https://sb1hub.gpcloud.com/pp/3c1e2f7f-22b6-4d42-be84-633003d2e4c1
alpha.pwstaging.com.au/docs/alphahpp#paypage-request-submission-
So, whether the «Pay Pages» paths should be kept secure (e.g., be encrypted in the Magento 2 database)?