Test · TST-SOC2-ENC-01
ENC-01 · Customer and payment data encrypted at rest and in transit
PassQ3 2026 Unified Program ReviewTested 3 Oct 2026 by Laura Bennett · Kestrel Assurance LLP
Requirement to validation
Requirement
ISO-A.8.24 · RBI-DPSC-2021-4 · SOC2-C1.1 · SOC2-CC6.1 · SOC2-CC6.7
mapped
Policy
Payments Security Policy
pol-payments
Control
ENC-01
Customer and payment data encrypted at rest and in transit
Application
Amazon Web Services (ap-south-1) · Meridian Customer Portal
mapped
Evidence · Q3
2 items
2 approved · 0 pending · 0 rejected
Test · Q3
Pass
TST-SOC2-ENC-01 · High confidence
Finding
None
Action
None
Validation
Not planned
Procedure and result
- Procedure
- AWS KMS CMKs, ALB TLS policy. Tests: Amazon Web Services (ap-south-1): RDS and S3 encryption enabled; Meridian Customer Portal: TLS configuration on portal endpoints. Frequency continuous.
- Sample
- 2 items sampled (reperformance)
- Expected
- Customer PII, KYC documents and payment data are encrypted at rest with KMS-managed keys and in transit with TLS 1.2+; keys are rotated annually.
- Observed
- Operating effectiveness confirmed for AWS, Meridian Customer Portal; no exceptions in 2 sample(s).
- Confidence
- High
- Evidence
- SOC2-REQ-035SOC2-REQ-036