What this standard answers
- Where encryption is required in transit and at rest
- Which key-management controls are required
- How exceptions are reviewed and approved
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Encryption and key-management requirements for hosted deployments.
| Area | Requirement |
|---|---|
| Data in transit | TLS is required for external API and service traffic |
| Data at rest | Cloud-provider encryption controls are required for databases, storage, and backups |
| Secrets | Managed secret systems are required; secrets are not stored in source code |
| Area | Requirement |
|---|---|
| Key services | Cloud key-management services |
| Access control | Least-privilege IAM and RBAC for key and secret administration |
| Rotation | Key lifecycle follows cloud-provider rotation and lifecycle controls |
| Credential lifecycle | Integration credentials are rotatable and revocable |
| Visibility | Key and encryption events are available through logging and monitoring paths |