Test · TST-Q2-ENC-01

ENC-01 · Customer and payment data encrypted at rest and in transit

PassQ2 2026 Unified Program ReviewTested 12 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit

Requirement to validation

Procedure and result

Procedure
AWS KMS CMKs, ALB TLS policy. Tests: Amazon Web Services (ap-south-1): RDS and S3 encryption enabled; Meridian Customer Portal: TLS configuration on portal endpoints. Frequency continuous.
Sample
25 items sampled (Q2 baseline)
Expected
Customer PII, KYC documents and payment data are encrypted at rest with KMS-managed keys and in transit with TLS 1.2+; keys are rotated annually.
Observed
No exceptions in the sample; encryption of sensitive data operated as designed.
Confidence
High