Control 01
Encryption in transit and at rest
Traffic to GHMAP is encrypted in transit, and stored workspace data is encrypted at rest by the managed infrastructure it runs on.
- Connections to ghmap.io and app.ghmap.io use TLS. Credentials and workspace payloads are not sent in clear text.
- Workspace records and uploaded files are held in managed Supabase Postgres and object storage, which encrypt data at rest.
- Public demo and inquiry forms collect business contact and product context only. GHMAP does not ask for bank details, patient records, or confidential contracts through them.
- Encryption alone does not keep one organization's records away from another. That is the isolation model in control 02.
