Test · TST-SOC2-ENC-01

ENC-01 · Customer and payment data encrypted at rest and in transit

PassQ3 2026 Unified Program ReviewTested 3 Oct 2026 by Laura Bennett · Kestrel Assurance LLP

Requirement to validation

Procedure and result

Procedure
AWS KMS CMKs, ALB TLS policy. Tests: Amazon Web Services (ap-south-1): RDS and S3 encryption enabled; Meridian Customer Portal: TLS configuration on portal endpoints. Frequency continuous.
Sample
2 items sampled (reperformance)
Expected
Customer PII, KYC documents and payment data are encrypted at rest with KMS-managed keys and in transit with TLS 1.2+; keys are rotated annually.
Observed
Operating effectiveness confirmed for AWS, Meridian Customer Portal; no exceptions in 2 sample(s).
Confidence
High