Skip to main content

Topic index

Cryptography and Data Protection

Learn how cryptographic constructions, key lifecycles, and data governance protect information across its complete lifecycle.

Topic index

Understand this domain

Pomerium coverage

Pomerium uses authenticated transport and managed cryptographic material for access sessions, identity assertions, and TLS. Application owners still choose data classification, storage protection, cryptographic constructions, key custody, retention, deletion, and migration for application data.

Limits

  • Encryption does not authorize an actor or prevent an authorized endpoint from exposing plaintext.
  • A strong algorithm does not correct weak key custody, nonce reuse, unsafe serialization, or an unauthenticated protocol.
  • Storage encryption protects only the threat boundaries that do not also expose the decryption key and authorized runtime.

Primary sources

2 learning paths

Paths for this topic

7 related guides

Guides in this topic

GuideCryptography and Data Protection

Protect the data lifecycle

Control collection, use, sharing, storage, logging, backup, recovery, retention, deletion, and sanitization for one data class.

Open this guide

20 related terms

Concepts in this topic

Security Operations and RiskCryptography and Data Protection

Backup and Restore

Create isolated, complete, recoverable copies and prove they restore current service without old compromise, authority, or expired data.

Learn this term
Cryptography and Data Protection

Cryptographic Agility

Inventory and replace algorithms, parameters, protocols, keys, libraries, certificates, and stored formats without hidden dependencies.

Learn this term
Cryptography and Data Protection

Data Classification

Assign data sensitivity, criticality, ownership, use, sharing, retention, and recovery requirements that drive technical controls.

Learn this term
Cryptography and Data Protection

Digital Signature

Bind a defined message to a private signing key and verify it through an authenticated public key, purpose, and context.

Learn this term
Cryptography and Data Protection

Envelope Encryption

Encrypt data with a data-encryption key and protect that key under a separately stored key-encryption key or key service.

Learn this term
Platform and Component SecurityCryptography and Data Protection

Hardware Root of Trust

Anchor a narrow security function in protected hardware while stating the manufacturing, firmware, key, lifecycle, and physical assumptions that remain.

Learn this term
Privacy EngineeringCryptography and Data Protection

Personal Data and Metadata

Treat identifiers, device facts, access events, relationships, timing, locations, and derived attributes as personal when context can link them to people.

Learn this term
Cryptography and Data Protection

Post-Quantum Cryptography

Prepare public-key systems for quantum-resistant key establishment and signatures through inventory, standards, testing, and migration.

Learn this term
Security Operations and RiskCryptography and Data Protection

Secure System Decommissioning

Remove a system, route, identity, key, dependency, and data without leaving reachable shadow service or breaking another security control.

Learn this term
Platform and Component SecurityCryptography and Data Protection

Side-Channel Attack

Analyze information leaked through time, caches, memory access, power, emissions, sound, faults, resources, and error behavior.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo