Data Encryption
TLS 1.3 in transit, AES-256 at rest for sensitive fields, and scheduled key rotation — encryption at every layer by default.
Data Encryption in YoApp is not a configurable option — it is on by default, at every layer. All data in transit is protected by TLS 1.3. Sensitive data at rest — identity numbers, account details, transaction amounts, and biometric records — is encrypted at the field level using AES-256. Encryption keys are managed in a dedicated key management service with scheduled rotation policies, so your data remains protected even if the underlying storage is ever compromised.
Everything you need, nothing you don't
TLS 1.3 Everywhere
All communication between clients and the platform — web browsers, mobile apps, API clients, USSD gateways — uses TLS 1.3. Older protocol versions are rejected at the network edge.
AES-256 Field Encryption
Sensitive data fields — national ID numbers, account numbers, mobile numbers, biometric hashes, and transaction amounts above a configurable threshold — are encrypted at the field level in the database.
Key Management Service
Encryption keys are stored and managed in a dedicated key management service — separate from the application database — with access restricted to the encryption service account only.
Scheduled Key Rotation
Encryption keys are rotated on a configurable schedule. Key rotation is seamless — existing data is re-encrypted in the background without downtime or application changes.
Database Encryption at Rest
The entire database storage volume is encrypted at rest using the cloud provider's native disk encryption — providing defence-in-depth against physical storage compromise.
Document Storage Encryption
Customer documents — identity scans, photos, certificates — are stored in an encrypted object store with server-side encryption and access controlled by the platform's permission system.
Encryption Key Access Log
Every encryption key access — read, rotation, backup — is logged in the security audit trail with the service account identity and timestamp.
Certificate Management
TLS certificates are monitored for expiry and renewed automatically before they expire — preventing the downtime and security gaps caused by forgotten certificate renewals.
Built for your team
Verify that your organisation's data is protected at every layer — transit, storage, and field level — with documented encryption standards and key management practices.
Demonstrate compliance with data protection regulations that require encryption of personal and financial data — with the encryption audit log as evidence.
Rely on encryption that is managed and maintained by the platform — eliminating the risk of misconfigured or expired certificates causing security gaps.
Ready to activate Data Encryption?
Sign up free and configure Data Encryption in minutes — or book a demo and we'll walk you through it live.