How to Answer Encryption-in-Transit Questions

Your customer asked: “Is customer data encrypted in transit?”

The short answer

The question is asking whether information is protected while moving between systems, users, or services. Verify the actual protocols and the scope of the data flows before answering. Do not assume that using a modern cloud platform means every transmission path is covered.

Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.

What the customer is really asking

Understand the question before you answer it.

Reviewers want to reduce the risk that data can be read or altered while it travels. Your answer should reflect the real customer-data paths that matter to your service, not a generic statement about encryption technology.

How to answer accurately

Start with the version that matches reality.

1

If relevant traffic is encrypted

Describe the scope and the mechanism at a level you can verify. If you name a protocol or version, confirm it from configuration or vendor documentation first.

2

If some transfers are outside your control

Explain which transfers are handled by third-party services or customers and avoid claiming universal coverage.

3

If you do not know

Ask the person who manages the application, hosting, file transfer, or network configuration. Do not infer encryption from a padlock icon alone.

A useful answer structure

Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.

Evidence that may help

These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.

  • TLS or service configuration
  • Hosting or SaaS provider documentation
  • Network or architecture documentation
  • Configuration screenshots or scans that show the relevant transport settings

What not to say

  • “All data is encrypted in transit” without mapping the relevant data flows.
  • A specific TLS version unless it has been verified.
  • That transport encryption means the data is also encrypted at rest.

How Oredra handles this

Answer it once. Keep the truth behind the answer.

Oredra keeps encryption-in-transit and encryption-at-rest as separate approved facts so they do not get merged into one broad claim.

Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.

Authoritative references

Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.

Related questionnaire questions