Standardele de criptare
Informațiile dumneavoastră rămân protejate la fiecare pas — TLS 1.2+ în tranzit și AES-256-GCM în repaus, folosind măsuri de protecție standard în industrie, în care puteți avea încredere.
Protecția Datelor în Tranzit
Toate datele transmise între browserul dumneavoastră și serverele noastre rămân protejate prin TLS.
- Doar TLS 1.2 și 1.3
- Suite de cifrare puternice (AES-GCM)
- HSTS activat cu preload
- Perfect Forward Secrecy
Protecție în Repaus
Datele sensibile stocate în baza noastră de date sunt criptate cu AES-256-GCM.
- Cifrare AES-256-GCM
- Chei separate pentru fiecare utilizator
- Suport pentru rotația cheilor
- Stocare sigură a cheilor
Ce este criptat?
Întotdeauna criptat
- Toate comunicațiile API
- Chei criptografice
- Datele de autentificare ale utilizatorului
- Token-urile de sesiune
Criptat la repaus
- Materialul de chei al utilizatorului
- Token-uri API
- Secrete 2FA
- Coduri de backup
Niciodată stocat
- Textul dumneavoastră original
- Conținutul procesat
- Conținutul documentelor
- PII detectat
How Your Data Is Protected
- 1
Encrypted connection
Every request travels over TLS 1.3 with Perfect Forward Secrecy. No plaintext ever crosses the wire.
- 2
In-memory processing only
Presidio AI analyzes and anonymizes text entirely in RAM. Your original content is never written to disk or stored in a database.
- 3
Keys derived with Argon2id
User encryption keys are derived from your password using Argon2id — the winner of the Password Hashing Competition — before being wrapped with AES-256-GCM.
- 4
Zero-Knowledge key storage
Your wrapped key is stored encrypted. The server never sees your plaintext key or password. Only you can unwrap it.
- 5
Asymmetric option with RSA-4096
For multi-party workflows, RSA-4096-OAEP encapsulates a session key so only the private key holder can deanonymize output.
Encryption Standards Reference
| Standard | Use Case | Key / Strength |
|---|---|---|
| TLS 1.3 | Data in transit | ECDHE + AES-GCM |
| AES-256-GCM | Data at rest | 256-bit |
| XChaCha20-Poly1305 | Zero-knowledge key storage | 256-bit |
| Argon2id | Password key derivation | PHC winner |
| RSA-4096-OAEP-SHA256 | Asymmetric key encapsulation | 4096-bit |