At rest. In transit. Always.
ActiveAll customer data is encrypted at rest with AES-256, and all connections use TLS 1.3 (1.2 minimum). Database backups are encrypted with separate keys, rotated quarterly. Secrets live in AWS KMS or GCP KMS depending on the customer’s region.
- AES-256 at rest
- TLS 1.3 in transit
- Quarterly key rotation
- Hardware-backed key storage