infrastructureVersion 1SOC2ISO27001NIST800-171
Encryption Standard
Operational detail of encryption in transit, at rest, in use, and in export.
Download PDFSHA-256 0e51e9833cd48867…
Encryption Standard
1. Purpose
Operational detail of how Rex Black applies cryptography across its stack. This is the "what goes where" companion to the Cryptography & Key Management Policy.
2. In transit
- HTTPS everywhere. All Rex Black domains serve exclusively over TLS 1.2 or TLS 1.3; TLS ≤ 1.1 is disabled at the load balancer.
- HSTS is enabled with a 1-year max-age and
includeSubDomains. - Internal service-to-service calls within AWS use VPC endpoints and AWS's ambient TLS for API calls.
- Email: outbound SES is TLS-required with opportunistic enforcement. DKIM and DMARC are configured on all Rex Black sending domains.
- Database connections (DynamoDB, RDS if introduced) use the AWS-provided TLS endpoints; plaintext endpoints are prohibited.
3. At rest
- DynamoDB: server-side encryption with
alias/rexblack/defaultKMS key on every table. This is enforced by an IaC policy; tables without customer-managed KMS fail CI. - S3: SSE-KMS on every bucket. Public bucket policies are blocked at the account level via Public Access Block.
- Vault items: envelope-encrypted: payload with AES-256-GCM
under a data key; data key wrapped by
alias/rexblack/vault; shared-item variants additionally wrapped by each recipient's X25519 public key. - SSM Parameter Store: SecureString only, wrapped by
alias/rexblack/secrets. - Lambda temporary storage:
/tmpis treated as ephemeral; nothing sensitive may persist across invocations. - Endpoint disk: laptops are required to run FileVault (macOS) or BitLocker (Windows) per the Endpoint Security Policy.
4. In use
- Secrets are read on-demand, cached in-memory at the Lambda container only for the duration of a request.
- Sensitive values are never logged. Structured logs use an allow-list of fields; redaction middleware strips known secret patterns.
5. Exports / portability
- Any export of Confidential or Restricted data leaves Rex Black systems only over an encrypted channel, and only after the receiving system's encryption posture is approved.
- Physical media (USB drives, CDs) are prohibited for data above Internal unless the device is hardware-encrypted (FIPS 140-2 validated) and the export is logged.
6. FIPS considerations (CMMC / CUI scope)
- For engagements that touch CUI, AWS KMS satisfies FIPS 140-2. The
application-layer vault shall, for CUI scope, route payload
encryption through
kms:Encrypt/kms:Decryptrather than local AES-GCM, accepting the latency trade-off. This switch is enabled per-tenant via a feature flag. - Where non-FIPS crypto is used on non-CUI data, that fact is documented on the data classification record and reviewed annually.
7. References
008-cryptography-and-key-management-policy.md009-data-classification-and-handling-policy.md021-logging-and-monitoring-policy.md
8. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.