MasterKeyProvider implementation for opendcb-data-protection backed by HashiCorp Vault's
Transit secrets engine (wrap/unwrap via Transit's encrypt/decrypt endpoints). Self-hosted,
no cloud vendor dependency — philosophically consistent with eventstore-postgres over Axon
Server. Depends only on opendcb-data-protection's MasterKeyProvider interface and Vault's
Java client; changes nothing in opendcb-data-protection itself.