Skip to Content
SecurityEncryption

Encryption

All data encrypted at rest and in transit.

At Rest

ResourceEncryption
RDS PostgreSQLAWS-managed KMS
S3AES-256 server-side encryption
OpenSearch ServerlessAWS-managed KMS
ElastiCache ValkeyAWS-managed (at-rest and in-transit)
Secrets ManagerAWS-managed KMS

In Transit (TLS)

ConnectionEncryption
User → ALBTLS 1.2+
Control Plane → Data PlaneTLS
Data Plane → BedrockTLS
EKS → RDS/ElastiCacheTLS

MCP Credentials

Stored in your Secrets Manager:

  • Encrypted with KMS
  • Accessed via IRSA (no static credentials)
  • Never logged or cached in plain text

Next

Authentication

Last updated on