Skip to main content

Encryption & Key Management

Protecting Data at Every Layer

Encryption is the most fundamental security control and typically the first item on any enterprise security questionnaire. ReGenesis encrypts all data in transit using TLS 1.2/1.3 and all data at rest using AES-256 encryption. This means that even if an attacker gains physical access to a hard drive or intercepts network traffic, the data is unreadable without the encryption keys.

Key management -- how encryption keys are created, stored, rotated, and destroyed -- is equally critical. ReGenesis uses AWS Key Management Service (KMS) as the foundation, with per-tenant encryption keys planned for GA and Bring Your Own Key (BYOK) capability for high-security clients who want to control their own keys. Field-level encryption provides an additional layer of protection for the most sensitive data: coaching transcripts, AI-generated psychological insights, and private coaching notes are encrypted individually so that database access alone is insufficient to read them.

McKinsey specifically requires encryption at rest and in transit as a baseline vendor security requirement. The ReGenesis encryption architecture exceeds this baseline by adding field-level encryption, per-tenant key isolation, and hardware-backed key storage through AWS KMS -- matching the security posture that McKinsey maintains for their own internal platforms.