| Document Owner | ITHENA Information Security |
|---|---|
| Review Frequency | At least annually and upon material changes to the application, hosting environment, cryptographic standards, or regulatory requirements. |
This policy establishes the requirements and procedures used by ITHENA to protect sensitive information processed, transmitted, or stored by all ITHENA products, platforms, and services (collectively, the "ITHENA Products") through appropriate encryption and cryptographic key management controls.
The objective is to ensure that cryptographic technologies are implemented consistently, securely, and in accordance with industry-standard security practices throughout the lifecycle of ITHENA Products data and infrastructure.
This policy applies to all ITHENA Products production and non-production environments where customer, confidential, regulated, authentication, or security-sensitive data may be processed or stored.
It applies to:
ITHENA requires encryption of sensitive and customer information both in transit and at rest where technically applicable.
All externally accessible ITHENA Products interfaces and supported integrations use secure encrypted communication protocols.
ITHENA Products require:
Obsolete or insecure communication protocols and cryptographic algorithms are not permitted for production use unless explicitly approved as a documented exception.
Customer and sensitive application data stored within infrastructure supporting ITHENA Products must be encrypted at rest using encryption capabilities provided by the database, operating system, storage platform, cloud provider, or approved encryption solution.
Where applicable, ITHENA Products use AES-256 or equivalent industry-standard encryption for stored data.
Encryption controls apply, where appropriate, to:
ITHENA uses established and widely accepted cryptographic algorithms and protocols.
Approved technologies include, as applicable:
Deprecated or vulnerable algorithms, including SSL, TLS 1.0, TLS 1.1, DES, 3DES, and weak hashing algorithms such as MD5 for security-sensitive purposes, are prohibited unless required for a documented legacy dependency and formally approved.
Encryption keys used by ITHENA Products are stored separately from encrypted application data wherever technically feasible.
Keys, secrets, passwords, tokens, and certificates are maintained using approved, access-controlled key-management or secrets-management mechanisms provided by the applicable hosting environment.
Examples may include enterprise or cloud-based Key Management Services, Hardware Security Module-backed services, secrets vaults, or equivalent protected repositories.
Cryptographic keys must not be stored:
Access to cryptographic keys is restricted according to the principles of least privilege and need-to-know.
Access is limited to authorized personnel and system services necessary for application operation.
Administrative access to encryption keys must, where supported, use:
Shared administrative accounts should be avoided wherever technically feasible.
Cryptographic keys must be generated using approved cryptographically secure mechanisms.
Keys must have sufficient strength for their intended use and must be generated using approved key-management platforms, cryptographic libraries, or infrastructure services.
Manually generated or weak encryption keys are prohibited for production use.
Cryptographic keys are rotated periodically and when circumstances indicate increased risk.
Rotation may occur based on:
Where automated key rotation is supported by the applicable infrastructure or key-management service, it should be enabled whenever operationally practical.
If a cryptographic key, certificate, secret, or credential is suspected of being compromised, ITHENA will promptly:
Customer notification will be performed where required by contractual, legal, or regulatory obligations.
Where encryption keys require backup for business continuity or disaster recovery purposes, backups must be protected using security controls equivalent to or stronger than those protecting the operational keys.
Backup keys must be:
Recovery procedures must ensure that only authorized personnel can restore protected cryptographic material.
Cryptographic keys that are no longer required must be securely revoked, disabled, or destroyed.
Key destruction must prevent subsequent unauthorized recovery or use of the key.
Keys may be destroyed when:
Where cloud-managed key-management services are used, provider-supported secure deletion mechanisms are used.
Application secrets, service-account credentials, API keys, tokens, and database credentials are treated as sensitive security information.
These credentials must be:
Production credentials must not be intentionally embedded within application source code.
Digital certificates used by ITHENA Products must be issued, maintained, renewed, and revoked through authorized processes.
ITHENA monitors certificate expiration dates and replaces certificates before expiration wherever operationally feasible.
Certificates suspected of compromise must be revoked or replaced as soon as practical.
Databases supporting ITHENA Products must use encryption at rest where supported by the underlying platform.
Sensitive database communication must use encrypted connections where technically supported.
Database access is restricted to authorized applications, services, and administrative personnel.
Encryption keys used for databases must be managed separately from database content where technically feasible.
Backups containing customer, confidential, or sensitive information must be encrypted at rest where supported.
Backup repositories must also be protected using access controls and authentication mechanisms consistent with the sensitivity of the information stored.
Backup encryption keys are subject to the same access-control and lifecycle-management requirements defined within this policy.
Access to key-management systems and significant cryptographic administration activities must be logged where supported by the underlying technology.
Logs may include:
Security-relevant logs are protected against unauthorized access and reviewed as appropriate based on security monitoring procedures.
Where practical, cryptographic key administration responsibilities are separated from application development responsibilities.
Production key access is limited to personnel with an authorized operational, infrastructure, or security responsibility.
Developers should not require routine access to production encryption keys.
Production cryptographic keys and secrets must not be intentionally reused in development or test environments.
Non-production environments should use separate credentials, certificates, and encryption keys.
Production customer data should not be used in non-production environments unless specifically authorized and appropriately protected.
Where ITHENA Products rely on approved hosting or cloud infrastructure providers, ITHENA may use the provider's native encryption, secrets-management, certificate-management, and key-management capabilities.
ITHENA remains responsible for configuring and managing those capabilities appropriately within ITHENA Products environments.
Third-party providers must maintain security controls appropriate for the services they provide.
Suspected loss, disclosure, or unauthorized access involving cryptographic keys, secrets, certificates, or encrypted information must be handled under ITHENA's Security Incident Management and Response procedures.
Security events involving cryptographic material are evaluated based on:
Root cause and corrective actions are documented for significant incidents.
Any exception to this policy must be:
Exceptions must be periodically reviewed and removed when they are no longer required.
Responsible for:
Responsible for:
Responsible for:
This policy is reviewed at least annually and when significant changes occur to:
Updates are approved by appropriate ITHENA technology or security leadership.
Failure to comply with this policy may result in removal of system access, corrective action, or other measures appropriate to the circumstances.
ITHENA reserves the right to implement additional cryptographic controls where required by customer, contractual, regulatory, or security requirements.
ITHENA Products protect sensitive information through encryption in transit and at rest, restricted access to cryptographic material, secure storage of encryption keys, controlled key rotation and revocation, secure credential management, and monitoring of key-management activities.
Encryption keys are maintained separately from protected data wherever technically feasible and are accessible only to authorized personnel and system services using role-based access controls and approved key-management mechanisms.