Transport Security
Guard's policy for data in transit: TLS 1.2 at minimum on platform endpoints, with TLS 1.3 preferred.
Praetorian encrypts data in transit with Transport Layer Security (TLS), preferring TLS 1.3. This article describes the protocol, cipher, certificate, and monitoring practices we apply.
1. Protocol Upgrades
- Adopting TLS 1.3: TLS 1.3 is our preferred protocol for transport security. It removes outdated mechanisms such as RSA key exchange and weak ciphers. TLS 1.2 is the minimum version we support.
2. Encryption in Transit
- Perfect Forward Secrecy (PFS): TLS 1.3 mandates ephemeral key exchanges, ensuring that even if a private key is compromised, past sessions remain secure.
- Secure Ciphers: Only strong cipher suites, such as AES-GCM and ChaCha20-Poly1305, are enabled.
3. Authentication and Trust
- Strict Certificate Validation: We apply strict validation practices to ensure certificates are issued only by trusted providers.
4. Performance and Efficiency
- Zero Round-Trip Time (0-RTT): Where applicable, we use 0-RTT for faster reconnections, with additional safeguards against replay attacks.
5. Compliance and Governance
- Compliance Standards: Our TLS 1.3 implementation adheres to industry compliance standards, including PCI DSS, GDPR, and SOC 2.
6. Monitoring and Incident Response
- Real-Time Threat Detection: Integrated monitoring systems detect anomalies in TLS traffic, such as downgrade attempts or suspicious activities.
- Logging: Logs of TLS handshake and session activities are kept for auditing and incident response.
More in Data Security
Secrets ManagementSecure DeleteStill need help? Ask the team