1. Purpose
The SCC Data Encryption Policy defines the encryption requirements used by the Specify Collections Consortium (SCC) to protect the confidentiality and integrity of member data stored, processed, or transmitted through SCC systems. This policy ensures that all data handled by SCC is protected using industry standard encryption methods that meet institutional, legal, and contractual expectations.
2. Scope
This policy applies to:
-
Specify Cloud hosted databases and assets
-
SCC managed servers, containers, and storage systems
-
Data transmitted between clients, servers, and APIs
-
Backups, snapshots, and logs
-
Authentication and credential workflows
-
All SCC staff, contractors, and authorized third parties
This policy covers both data at rest and data in transit.
3. Encryption Standards
Data in Transit
All data transmitted between clients, servers, and SCC managed services are encrypted using:
-
TLS 1.2 or higher
-
HTTPS for all web based communication
-
SSH for administrative access
Data at Rest
Specify Cloud encrypts all data within SCC managed environments using:
-
AES 256 encryption for AWS RDS, S3 buckets and object storage
-
Encrypted Docker volumes for local development and staging environments
Encryption keys are managed through AWS Key Management Service.
4. Database Encryption
All Specify Cloud databases use encryption at rest through Amazon RDS for MariaDB using AWS Key Management Service (AWS KMS) to provide Transparent Data Encryption (TDE) at the underlying storage level.
5. Asset Storage Encryption
Specify Cloud stores all digital assets, including images, documents, and attachments in encrypted S3 buckets. Public access is blocked. Access is restricted to SCC systems and authorized staff.
6. Backup Encryption
Specify Cloud ensures backups are encrypted at rest and in transit. This includes:
-
Database backups
-
Asset snapshot including incremental updates
Specify Cloud stores backups in the same region as the member’s hosting environment to maintain data residency compliance.
7. Password and Credential Encryption
Local Authentication in Specify
Specify uses a multi step process to protect passwords, described in more detail here: Passwords in Specify
Passwords are never stored or transmitted in plain text.
API Authentication
API authentication uses session based tokens. Tokens are transmitted only over HTTPS and stored securely by the client.
Credential Storage
SCC stores all credentials used by the SCC team in Bitwarden using:
-
Encrypted vaults
-
Role based access
-
Regular access reviews
-
Immediate revocation when no longer required
8. Key Management
Encryption keys are managed by AWS Key Management Service. SCC does not store or manage raw encryption keys.
9. Data Isolation and Multi Tenancy
Member data is logically isolated in multi-tenant environments. Encryption ensures that data belonging to one institution cannot be accessed by another. Single tenant hosting is available for institutions requiring dedicated infrastructure.
10. Prohibited Data
Specify and the SCC do not support collection or storage of regulated data such as PHI, PCI, or sensitive PII, protected health information, payment card data, or other highly sensitive personal data.
11. Logging and Encryption
SCC logs do not contain sensitive data such as passwords or full authentication tokens.
12. Encryption Compliance
SCC does not currently certify to a specific framework but maintains controls consistent with SOC 2 and ISO 27001 encryption requirements.
13. Exceptions
Any exception to this policy must be approved by the SCC Executive Director. Exceptions must be documented and time-limited.
14. Policy Review
SCC staff reviews this policy annually and updates as SCC infrastructure, hosting practices, and member needs evolve.
Download this document as a pdf:
SCC Data Encryption Policy.pdf (100.1 KB)