TARE wordmark
Back to Knowledge Base

Data Encryption

How we protect your data at rest and in transit using industry-standard cryptography.

TARE combines application controls with managed infrastructure security features. The exact encryption, backup, and network-control posture depends on the deployed environment and must be confirmed during a production security review.

Encryption at Rest

  • Database: Production data uses provider-managed encryption at rest.
  • Backups: Backup encryption and retention follow the selected provider configuration.
  • Files: Configured S3/R2 object storage uses server-side encryption controls.

Encryption in Transit

  • TLS: Web and API traffic is protected through the configured edge and provider endpoints.
  • HSTS: Production web responses use transport-security policy where configured.
  • Verification: Protocol and cipher posture should be checked against the actual production hostname.