How to Answer Encryption-in-Transit Questions
Your customer asked: “Is customer data encrypted in transit?”
The short answer
The question is asking whether information is protected while moving between systems, users, or services. Verify the actual protocols and the scope of the data flows before answering. Do not assume that using a modern cloud platform means every transmission path is covered.
Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.
What the customer is really asking
Understand the question before you answer it.
Reviewers want to reduce the risk that data can be read or altered while it travels. Your answer should reflect the real customer-data paths that matter to your service, not a generic statement about encryption technology.
How to answer accurately
Start with the version that matches reality.
If relevant traffic is encrypted
Describe the scope and the mechanism at a level you can verify. If you name a protocol or version, confirm it from configuration or vendor documentation first.
If some transfers are outside your control
Explain which transfers are handled by third-party services or customers and avoid claiming universal coverage.
If you do not know
Ask the person who manages the application, hosting, file transfer, or network configuration. Do not infer encryption from a padlock icon alone.
A useful answer structure
Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.
Evidence that may help
These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.
- TLS or service configuration
- Hosting or SaaS provider documentation
- Network or architecture documentation
- Configuration screenshots or scans that show the relevant transport settings
What not to say
- “All data is encrypted in transit” without mapping the relevant data flows.
- A specific TLS version unless it has been verified.
- That transport encryption means the data is also encrypted at rest.
How Oredra handles this
Answer it once. Keep the truth behind the answer.
Oredra keeps encryption-in-transit and encryption-at-rest as separate approved facts so they do not get merged into one broad claim.
Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.
Authoritative references
Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.
Related questionnaire questions
Is customer data encrypted at rest?
Encryption at rest concerns stored data. Before answering, identify where customer information is stored and confirm which storage systems, databases, devices, and backups are actually encrypted.
How long do you retain customer data, and how is it deleted?
Describe the actual retention and deletion practice for the data in scope. Be especially careful with fixed timelines, backups, legal or contractual retention, and copies held by subprocessors because those details can make a simple answer inaccurate.