Skip to main content

Encryption & Key Management

Protecting Data at Every Layer​

Encryption is the most fundamental security control and typically the first item on any enterprise security questionnaire. ReGenesis encrypts all data in transit using TLS 1.2/1.3 and all data at rest using AES-256 encryption. This means that even if an attacker gains physical access to a hard drive or intercepts network traffic, the data is unreadable without the encryption keys.

Key management -- how encryption keys are created, stored, rotated, and destroyed -- is equally critical. ReGenesis uses AWS Key Management Service (KMS) as the foundation, with per-tenant encryption keys planned for GA and Bring Your Own Key (BYOK) capability for high-security clients who want to control their own keys. Field-level encryption provides an additional layer of protection for the most sensitive data: coaching transcripts, AI-generated psychological insights, and private coaching notes are encrypted individually so that database access alone is insufficient to read them.

McKinsey specifically requires encryption at rest and in transit as a baseline vendor security requirement. The ReGenesis encryption architecture exceeds this baseline by adding field-level encryption, per-tenant key isolation, and hardware-backed key storage through AWS KMS -- matching the security posture that McKinsey maintains for their own internal platforms.