Control · ENC-01

Customer and payment data encrypted at rest and in transit

Data ProtectionSOC 2 · ISO 27001 · RBIRisk Medium

Requirement to validation

What should be true

Customer PII, KYC documents and payment data are encrypted at rest with KMS-managed keys and in transit with TLS 1.2+; keys are rotated annually.

Requirements
ISO-A.8.24 A.8.24 · Use of cryptography
RBI-DPSC-2021-4 RBI-DPSC-2021 §4 · Digital payment security — application security, API security, transaction authentication (RBI Master Direction on Digital Payment Security Controls, 2021)
SOC2-C1.1 C1.1 · Identifies and maintains confidential information
SOC2-CC6.1 CC6.1 · Logical access security software, infrastructure and architectures
SOC2-CC6.7 CC6.7 · Restricts transmission and movement of information; encryption in transit
Testing procedure
AWS KMS CMKs, ALB TLS policy. Tests: Amazon Web Services (ap-south-1): RDS and S3 encryption enabled; Meridian Customer Portal: TLS configuration on portal endpoints. Frequency continuous.

Findings (0)

Open list →
○ No data available

Evidence (4)

Open list →
EvidenceTitleControlSource systemCollectedStatus
Q2-EV-030Amazon Web Services (ap-south-1) · system export (Q2)ENC-01Amazon Web Services (ap-south-1)9 Jun 2026Accepted
Q2-EV-031Meridian Customer Portal · configuration report (Q2)ENC-01Meridian Customer Portal14 Jun 2026Accepted
SOC2-REQ-035AWS: RDS and S3 encryption enabledENC-018 Oct 2026Accepted
SOC2-REQ-036Meridian Customer Portal: TLS configuration on portal endpointsENC-01Meridian Customer Portal7 Oct 2026Accepted

Tests (2)

Open list →
TestControlCycleTestedByResultConfidence
TST-SOC2-ENC-01ENC-01 · Customer and payment data encrypted at rest and in transitQ3 2026 Unified Program Review3 Oct 2026Laura Bennett · Kestrel Assurance LLPPassHigh
TST-Q2-ENC-01ENC-01 · Customer and payment data encrypted at rest and in transitQ2 2026 Unified Program Review12 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditPassHigh