Describe how customer data is encrypted at rest and in transit.
Customer data is encrypted at rest using AES-256 across all production data stores and backups, and in transit using TLS 1.2 or higher with legacy protocols disabled.
Mapped evidence
- SEC-ENC-001Encryption at RestCurrent
- SEC-ENC-002Encryption in TransitCurrent
Strong control match on current, approved evidence with no sensitivity flags — cleared to auto-approve.