Confirmation of Encryption Mechanism for Data at Rest and Data in Transit – Vault Enterprise v1.21.2+ent.hsm

Hi Team,

We are using HashiCorp Vault Enterprise v1.21.2+ent.hsm.

We require an official confirmation regarding the encryption mechanisms used by Vault for audit/compliance purposes.

Could you please confirm the following for Vault Enterprise v1.21.2+ent.hsm:

  1. Whether encryption is applied for data at rest and data in transit.
  2. The encryption algorithm used for data at rest and its key size.
  3. The encryption mechanism/protocol used for data in transit, including the supported TLS versions and the encryption algorithm/key size used during communication.
  4. Please provide any official product documentation or references that can be used as evidence for audit/compliance purposes.

We have referred to the Vault Security Model documentation but require official confirmation for our deployed version.

Thank you.

I would suggest working with your account manager or support to get to the specifics here.