Glossary

    Encryption in Transit

    Data Protection

    Encryption in Transit protects data while it travels over a network - between your application and an AWS service, between AWS services, or between your users and your application. The most common protocol is TLS (Transport Layer Security).

    AWS Implementation

    • HTTPS: all AWS API endpoints use TLS by default
    • ACM: free TLS certificates for CloudFront, ALB, API Gateway
    • VPN: encrypted IPsec tunnels for hybrid connectivity
    • Direct Connect: private dedicated connection (not encrypted by default; use MACsec for link-layer encryption or layer a VPN on top for IPsec encryption)
    • Post-Quantum TLS: available on CloudFront since September 2025 for protection against harvest-now-decrypt-later attacks

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.