- Data at Rest: All sensitive data (credentials, tokens, secrets) is encrypted using AES-256-GCM encryption
- Data in Transit: All communications use TLS 1.2 or higher encryption
- Encryption Keys: Encryption keys are managed securely and stored separately from encrypted data
- Key Management: Production environments require secure, hex-encoded 32-byte encryption keys