Security Controls
Encryption
How we encrypt data at rest and in transit, including our minimum TLS standard and how we handle passwords and cryptographic keys.
Last reviewed: July 2026
Encryption encodes data so that it remains hidden from or inaccessible to unauthorized users. By encrypting data at rest and in transit, we better protect private, proprietary, and critical data and enhance communication security between client applications and servers. This page describes how we approach encryption at Risely.
Our approach
We secure both data at rest and data in transit. Data at rest is physically stored data, encrypted using tools managed by our infrastructure providers. Data in transit, which is actively moving between locations, is encrypted using TLS and trusted security certificates. Passwords and cryptographic keys are encrypted and stored securely. We do not build our own cryptography.
This applies to the systems and networks that store and transfer critical data, including cloud-hosted vendor services, endpoints, production networks, and cloud assets used in delivering Risely’s services. It may also extend to third-party systems that support our business.
Encryption at rest
Data at rest is data that is physically stored and not actively moving from one location to another, such as data stored on laptops, flash drives, and hard drives. We encrypt data at rest using a variety of tools, including managed databases provided by our infrastructure providers that offer options to encrypt data at rest, and by using the infrastructure provider’s option to encrypt the underlying storage of assets that persist data. In these cases, encryption keys are managed by the infrastructure provider.
Encryption in transit
Data in transit is data that is actively moving from one location to another, including data transferred over public networks such as the Internet. We encrypt data in transit using a variety of tools, including:
- TLS: we always use HTTPS with SSL enabled. Our minimum standard is TLS v1.2.
- Security certificates from a known, trusted provider for all of Risely’s public-facing properties on the Internet.
Building our own cryptography
We do not build our own cryptography. Where an edge case appears to call for it, we work to find a suitable alternative instead.
Password encryption
All passwords of end-users and customers are encrypted in transit and when stored at rest within the application or database.
Cryptographic keys
Cryptographic keys are generated and stored in a secure manner that prevents collision, loss, theft, or compromise.
Questions
If you have any questions about this policy, contact us at [email protected].
Questions about this policy? [email protected]
