01
Data protection
Customer data is encrypted at rest using AES-256 and in transit using TLS 1.3 with modern cipher suites. Field-level encryption is available for named PII fields. Keys are managed in a FIPS 140-2 Level 3 HSM-backed KMS, with customer-managed key (CMK) options on AWS, GCP, and Azure.
- AES-256 at rest, TLS 1.3 in transit
- FIPS 140-2 Level 3 HSM-backed KMS
- Optional customer-managed keys (BYOK)
- Field-level encryption for named PII