Security & Compliance

Data Encryption

TLS 1.3 in transit, AES-256 at rest for sensitive fields, and scheduled key rotation — encryption at every layer by default.

Get Started Free

Data Encryption in YoApp is not a configurable option — it is on by default, at every layer. All data in transit is protected by TLS 1.3. Sensitive data at rest — identity numbers, account details, transaction amounts, and biometric records — is encrypted at the field level using AES-256. Encryption keys are managed in a dedicated key management service with scheduled rotation policies, so your data remains protected even if the underlying storage is ever compromised.

TLS 1.3 in transit AES-256 at rest Field-level encryption Key rotation policies Key management service Encryption audit log
What's included

Everything you need, nothing you don't

TLS 1.3 Everywhere

All communication between clients and the platform — web browsers, mobile apps, API clients, USSD gateways — uses TLS 1.3. Older protocol versions are rejected at the network edge.

AES-256 Field Encryption

Sensitive data fields — national ID numbers, account numbers, mobile numbers, biometric hashes, and transaction amounts above a configurable threshold — are encrypted at the field level in the database.

Key Management Service

Encryption keys are stored and managed in a dedicated key management service — separate from the application database — with access restricted to the encryption service account only.

Scheduled Key Rotation

Encryption keys are rotated on a configurable schedule. Key rotation is seamless — existing data is re-encrypted in the background without downtime or application changes.

Database Encryption at Rest

The entire database storage volume is encrypted at rest using the cloud provider's native disk encryption — providing defence-in-depth against physical storage compromise.

Document Storage Encryption

Customer documents — identity scans, photos, certificates — are stored in an encrypted object store with server-side encryption and access controlled by the platform's permission system.

Encryption Key Access Log

Every encryption key access — read, rotation, backup — is logged in the security audit trail with the service account identity and timestamp.

Certificate Management

TLS certificates are monitored for expiry and renewed automatically before they expire — preventing the downtime and security gaps caused by forgotten certificate renewals.

Who uses this module

Built for your team

CISOs & Security Teams

Verify that your organisation's data is protected at every layer — transit, storage, and field level — with documented encryption standards and key management practices.

Compliance Officers

Demonstrate compliance with data protection regulations that require encryption of personal and financial data — with the encryption audit log as evidence.

IT & Infrastructure Teams

Rely on encryption that is managed and maintained by the platform — eliminating the risk of misconfigured or expired certificates causing security gaps.

Ready to activate Data Encryption?

Sign up free and configure Data Encryption in minutes — or book a demo and we'll walk you through it live.

Get Started Free