Encryption, logging and security

The law requires reasonable security measures proportionate to the sensitivity of the information. The choices below are common good practices.

Encryption

  • In transit: TLS 1.2 minimum, TLS 1.3 preferred; HSTS.
  • At rest: AES-256 (database, disks, backups).
  • Keys: in a KMS or Vault, with rotation and separation of duties (who encrypts ≠ who administers).

Logs without personal information

Logs (Datadog, Sentry, ELK, CloudWatch) are a frequent leak source: emails in URLs, tokens in headers, full JSON payloads in stack traces.

import re

PATTERNS = [
    (re.compile(r"[\w.+-]+@[\w-]+\.[\w.]+"), "[email]"),
    (re.compile(r"Bearer\s+[A-Za-z0-9._-]+"), "Bearer [token]"),
    (re.compile(r"\b\d{3}[ -]?\d{3}[ -]?\d{3}\b"), "[number]"),
]

def scrub(message: str) -> str:
    for pattern, repl in PATTERNS:
        message = pattern.sub(repl, message)
    return message

Also configure redaction at the source (Sentry beforeSend, Datadog exclusion rules, Logstash processors) rather than relying on after-the-fact cleanup alone.

Audit and log retention

An audit log of access to PI (who, what, when), limited retention and restricted access to logs.