Data Encryption
Last Updated: Tuesday, 01 January 2017 02:43AM v091bh12
We employ various techniques to protect and preserve client data, from one way hashing to in-transit encryption.
- Only standard, robust encryption libraries are deployed across EC2 (certified)
- RDS (AWS managed Database services)
- S3 data versioning and bucket encryption
- AWS API (SDK or boto3 based) request signing
- KMS key deployments (generating and preserving keys attached to Client AWS account)
- AWS STS token service
- SSL in transit encryption can be assigned on ELB/ALB level, or supplied by the Client. Additionally, we are running our own LE (Let's Encrypt) authority hubs and can (pending DNS routing) generate and renew strong SSL (AAA grade) certificates