Encryption & key management

How data is protected in transit and at rest on the managed stack — plus BYOB and roadmap.

We do not offer uncapped cryptographic warranties. BYOB shifts key custody and policy enforcement to your cloud account.

In transit

Browser and API traffic is protected with TLS using modern cipher suites. Custom hostnames use your own zone's TLS configuration when applicable.

At rest (platform)

Object storage, relational metadata, and every other managed service we bind rely on provider-managed encryption and enforced access boundaries. Our infrastructure providers are named in the subprocessor list, where you can review their own trust documentation.

BYOB

When you attach your bucket, encryption keys and bucket policies are yours to configure (SSE-KMS, dual-layer, etc.).

Roadmap: customer-managed keys (CMK)

We track demand for tenant-scoped key hierarchies or customer-held keys for selected payloads. Availability depends on what the underlying key-management features allow — not promised on a fixed date.