# Data Encryption | EternalEngine Security

Encrypted at rest and in transit. AES-256-GCM for stored data, TLS 1.3 for traffic, and automatic key rotation — bank-grade by default.

Security & Compliance

# Encrypted at rest. Encrypted in transit.

Your data is protected by AES-256-GCM encryption while stored and TLS 1.3 while in transit. Keys rotate automatically. No configuration required — bank-grade protection is the default, not an upgrade.

[Start free](https://app.eternalengineos.io/signup?plan=free&interval=annual)[View all security →](https://eternalengineos.io/features/security-compliance/)

Encryption Architecture

Your Browser / App

Contact data, deals, notes

TLS 1.3 — In Transit

EternalEngine API

Auth verified, tenant scoped

AES-256-GCM — At Rest

PostgreSQL Database

Encrypted fields

·

RLS active

·

Key rotation

## Encryption at every layer

Protecting your data isn't one switch — it's a layered strategy covering storage, transport, and key lifecycle.

### AES-256-GCM at Rest

Sensitive fields — contact details, notes, deal values — are encrypted using AES-256-GCM before being written to the database. The raw data is never stored in plaintext.

### TLS 1.3 in Transit

All data between your browser, our API, and our database travels over TLS 1.3 — the most secure transport protocol available. Older, vulnerable versions are explicitly rejected.

### Automatic Key Rotation

Encryption keys rotate automatically on a defined schedule. Old keys are retired, new keys are used for new data, and re-encryption of existing data occurs without downtime.

### Zero Config Required

Encryption is on by default for every account. There are no settings to enable, no tiers to upgrade to, no certificates to manage. Security is the baseline — not an option.

## Protection that never sleeps

Encryption isn't a feature you turn on. It's the foundation everything else is built on.

### Bank-Grade Protection

AES-256 is the same encryption standard used by financial institutions and governments worldwide. Your customer data deserves — and gets — that same level of protection.

### Regulatory Compliance

GDPR Article 32, HIPAA technical safeguards, and PCI-DSS all require encryption of sensitive data. EternalEngine satisfies these requirements out of the box — for every customer.

### Peace of Mind

Even if a disk were physically stolen, or a database backup intercepted, the data is useless without the encryption keys. Your customer data is protected at every layer, always.

Questions

## Common questions, straight answers.

### Keep exploring

- [All security features](https://eternalengineos.io/features/security-compliance/)
- [AssetVault file storage](https://eternalengineos.io/features/assetvault/)
- [Tenant isolation](https://eternalengineos.io/features/security-compliance/tenant-isolation/)
- [Plans and pricingFree to start; every paid plan has a 30-day free trial.](https://eternalengineos.io/pricing/)

What is encrypted at rest?

The database and file storage, using AES-256, with keys managed outside the application code.

What about data in transit?

All traffic between your browser, the API and the services runs over TLS.

Are stored secrets and credentials protected?

Yes. Integration credentials and connection configs are validated and stored encrypted, and secrets never appear in logs.

## Run your business from one place.

Five plans, seventeen launch apps, one dashboard. Set up in under 5 minutes — change tiers any time.

[Start free$0 forever &bull; No card &bull; Upgrade any time](https://app.eternalengineos.io/signup?plan=free&interval=annual)[Talk to Sales](https://eternalengineos.io/contact/)

From $0 · Basic $9.95/mo · Save 20% on annual billing · Upgrade or downgrade any time
