Data Privacy and Protection
Key and Secrets Management
Encryption keys are managed in AWS Key Management Service within our own account, with access restricted to the production role that needs it. Application secrets and credentials are held in a managed secret store, never in source code, and source repositories are scanned to enforce this.
Framework requirements this speaks to
- ISO 27001 A.8.24 (use of cryptography)
- ISO 27001 A.5.17 (authentication information)
Framework references are indicative: they show which requirement a control speaks to, so you can line it up against your own checklist. The authoritative mapping is the one in our SOC 2 report and our ISO 27001 Statement of Applicability, both available under NDA.
Need the evidence behind this?
Our SOC 2 report and ISO 27001 Statement of Applicability are the authoritative record. Both are available under NDA, by email - we do not host them as downloads.