summaryrefslogtreecommitdiff
path: root/genesishosting/security/security-encryption-standards.md
diff options
context:
space:
mode:
Diffstat (limited to 'genesishosting/security/security-encryption-standards.md')
-rw-r--r--genesishosting/security/security-encryption-standards.md23
1 files changed, 23 insertions, 0 deletions
diff --git a/genesishosting/security/security-encryption-standards.md b/genesishosting/security/security-encryption-standards.md
new file mode 100644
index 0000000..6d9139c
--- /dev/null
+++ b/genesishosting/security/security-encryption-standards.md
@@ -0,0 +1,23 @@
+# Encryption Standards
+
+Encryption is applied to all data in transit and at rest across Genesis Hosting Technologies infrastructure.
+
+## In Transit
+
+- HTTPS via TLS 1.3 (minimum TLS 1.2 for legacy fallback)
+- SFTP for all file transfers
+- SSH for all administrative access
+- rclone with TLS for object storage replication
+
+## At Rest
+
+- ZFS encryption on backup pools
+- PostgreSQL encryption at the database or filesystem level
+- WHMCS and DirectAdmin credentials hashed and salted
+- Backups encrypted with AES-256 before remote transfer
+
+## Key Management
+
+- SSH keys rotated every 6 months
+- Let's Encrypt certs auto-renew every 90 days
+- Master encryption keys stored offline and version-controlled