What the buyer is really asking
This is about data on the wire: between the buyer's users and your service, and between your service and its subprocessors. State your minimum TLS version and say whether traffic between your own internal services is encrypted too.
Other ways buyers ask it
Every one of these wants the same answer:
- “Is data encrypted in transit?”
- “What TLS version do you support?”
- “Do you disable weak ciphers and older protocols?”
- “Is traffic between internal services encrypted?”
Evidence to have ready
- A TLS scan result for your public endpoints
- Load balancer or CDN configuration showing the minimum TLS policy
- The cryptography section of your security policy
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.
Related data protection questions
- Describe your cryptographic key management: generation, rotation, revocation, and destruction of keys.
- How do you manage and rotate encryption keys?
- Can customers supply, manage, or revoke their own encryption keys (BYOK or customer-managed keys) for the data you hold on their behalf?
- How do you manage secrets including API keys, credentials, and certificates?