Skip to main content

Encryption Standards

CRYMBO follows industry-standard cryptographic protocols across all layers of the architecture.

Algorithms

PurposeAlgorithmKey Size
PII EncryptionRSA-OAEP / ECIES2048-bit RSA or P-256 EC
Data at RestAES-256-GCM256-bit
TransportTLS 1.3Per TLS specification
HashingSHA-256 / SHA-3256-bit
Digital SignaturesECDSA / EdDSAP-256 or Ed25519
Attestation SigningECDSAP-256

Compliance Standards

StandardCompliance
SOC 2 Type IIInfrastructure security controls
ISO 27001Information security management
GDPRData protection and privacy
IVMS101Identity data model standard

Key Management

  • Private keys are never stored by CRYMBO
  • HSM-backed key storage recommended for all institutions
  • Key rotation recommended every 90 days
  • Compromised keys can be revoked immediately via the CRYMBO Platform