Skip to main content
Last reviewed: March 5, 2026 Owner: Security + Engineering Review cadence: Quarterly Status: Implemented This standard defines encryption and key-management requirements for hosted deployments.

What this standard answers

  • Where encryption is required in transit and at rest
  • Which key-management controls are required
  • How exceptions are reviewed and approved

Implementation status (March 5, 2026)

The encryption and key-management requirements on this page are active in hosted production systems.

Scope

Applies to production systems, data stores, backups, service-to-service paths, and secrets handling.

Encryption requirements

Key-management requirements

Exceptions and governance

Exceptions require documented risk acceptance, Security and Engineering approval, compensating controls, and a time-bound remediation plan. Questions: