SCC Data Encryption Policy

1. Purpose

The SCC Data Encryption Policy defines the encryption requirements used by the Specify Collections Consortium (SCC) to protect the confidentiality and integrity of member data stored, processed, or transmitted through SCC systems. This policy ensures that all data handled by SCC is protected using industry standard encryption methods that meet institutional, legal, and contractual expectations.

2. Scope

This policy applies to:

  • Specify Cloud hosted databases and assets

  • SCC managed servers, containers, and storage systems

  • Data transmitted between clients, servers, and APIs

  • Backups, snapshots, and logs

  • Authentication and credential workflows

  • All SCC staff, contractors, and authorized third parties

This policy covers both data at rest and data in transit.

3. Encryption Standards

Data in Transit

All data transmitted between clients, servers, and SCC managed services are encrypted using:

  • TLS 1.2 or higher

  • HTTPS for all web based communication

  • SSH for administrative access

Data at Rest

Specify Cloud encrypts all data within SCC managed environments using:

  • AES 256 encryption for AWS RDS, S3 buckets and object storage

  • Encrypted Docker volumes for local development and staging environments

Encryption keys are managed through AWS Key Management Service.

4. Database Encryption

All Specify Cloud databases use encryption at rest through Amazon RDS for MariaDB using AWS Key Management Service (AWS KMS) to provide Transparent Data Encryption (TDE) at the underlying storage level.

5. Asset Storage Encryption

Specify Cloud stores all digital assets, including images, documents, and attachments in encrypted S3 buckets. Public access is blocked. Access is restricted to SCC systems and authorized staff.

6. Backup Encryption

Specify Cloud ensures backups are encrypted at rest and in transit. This includes:

  • Database backups

  • Asset snapshot including incremental updates

Specify Cloud stores backups in the same region as the member’s hosting environment to maintain data residency compliance.

7. Password and Credential Encryption

Local Authentication in Specify

Specify uses a multi step process to protect passwords, described in more detail here: Passwords in Specify

Passwords are never stored or transmitted in plain text.

API Authentication

API authentication uses session based tokens. Tokens are transmitted only over HTTPS and stored securely by the client.

Credential Storage

SCC stores all credentials used by the SCC team in Bitwarden using:

  • Encrypted vaults

  • Role based access

  • Regular access reviews

  • Immediate revocation when no longer required

8. Key Management

Encryption keys are managed by AWS Key Management Service. SCC does not store or manage raw encryption keys.

9. Data Isolation and Multi Tenancy

Member data is logically isolated in multi-tenant environments. Encryption ensures that data belonging to one institution cannot be accessed by another. Single tenant hosting is available for institutions requiring dedicated infrastructure.

10. Prohibited Data

Specify and the SCC do not support collection or storage of regulated data such as PHI, PCI, or sensitive PII, protected health information, payment card data, or other highly sensitive personal data.

11. Logging and Encryption

SCC logs do not contain sensitive data such as passwords or full authentication tokens.

12. Encryption Compliance

SCC does not currently certify to a specific framework but maintains controls consistent with SOC 2 and ISO 27001 encryption requirements.

13. Exceptions

Any exception to this policy must be approved by the SCC Executive Director. Exceptions must be documented and time-limited.

14. Policy Review

SCC staff reviews this policy annually and updates as SCC infrastructure, hosting practices, and member needs evolve.


Download this document as a pdf:
SCC Data Encryption Policy.pdf (100.1 KB)