Engineering Policy
Encryption Policy
Define encryption requirements for data in transit and at rest.
Summary
Policy overview
Scope
All company and customer data, including backups and portable media.
Objectives
- Require current protocol versions in transit
- Require encryption at rest for stored data
- Require managed key services
- Prohibit deprecated algorithms
What the policy covers
- TLS is required for all external communication.
- Data at rest is encrypted through platform-managed services.
- Keys are managed by the platform, never embedded in code.
- Deprecated protocols and ciphers are disabled.
Governance
Cryptographic choices are reviewed during design review and reassessed as guidance evolves.
Framework references
- NIST SP 800-171 3.13
- FIPS 140 validated modules where required
These are public governance summaries. Full policy text, operational procedures, runbooks, and configuration standards are not published and are provided under NDA or contract where a review requires them.
Related
More Engineering policies
Secure Development Policy
Integrate security requirements and verification into the development lifecycle.
AI Governance Policy
Govern the responsible use of artificial intelligence in development and service delivery.
IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.
Requesting security documentation?
Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.