Back to Knowledge Base
Data Encryption
How we protect your data at rest and in transit using industry-standard cryptography.
TARE combines application controls with managed infrastructure security features. The exact encryption, backup, and network-control posture depends on the deployed environment and must be confirmed during a production security review.
Encryption at Rest
- • Database: Production data uses provider-managed encryption at rest.
- • Backups: Backup encryption and retention follow the selected provider configuration.
- • Files: Configured S3/R2 object storage uses server-side encryption controls.
Encryption in Transit
- • TLS: Web and API traffic is protected through the configured edge and provider endpoints.
- • HSTS: Production web responses use transport-security policy where configured.
- • Verification: Protocol and cipher posture should be checked against the actual production hostname.
