Data protection · 12 answer guides
How to answer data protection questions in a security questionnaire
Encryption at rest and in transit, key management, retention, and where customer data lives. Almost every security questionnaire asks about these, because they tell a buyer whether their data is safe with you.
Encryption at rest
Describe your data encryption at rest strategy.Encryption in transit
What protocols and standards are used for data in transit encryption (e.g., TLS 1.2+)?Cryptographic key management
Describe your cryptographic key management: generation, rotation, revocation, and destruction of keys.Encryption key rotation
How do you manage and rotate encryption keys?Customer-managed keys (BYOK)
Can customers supply, manage, or revoke their own encryption keys (BYOK or customer-managed keys) for the data you hold on their behalf?Secrets management
How do you manage secrets including API keys, credentials, and certificates?Tenant data isolation
How do you isolate data between different tenants or customers?Data retention and destruction
Describe your data retention and destruction policies.Data classification
How do you classify and label data?Where sensitive data is stored
Where do you store sensitive/regulated data?Personnel access to customer data
Which groups of personnel (employees and contractors) have access to personal and sensitive data?Masking data in non-production
How do you mask, anonymize, or tokenize sensitive data in non-production environments?