Welcome to Portal

?Unknown\pull-down

Welcome to Zoho Cares

Bienvenido a Soporte de Zoho

Search our knowledge base, ask the community or submit a request.

Data Encryption in Zoho Recruit

Encryption is primarily used to safeguard the content of a message so that only the intended recipients can read it. This is done by replacing the content with unrecognizable data, which can be understood only by the intended recipient. Encryption has become a vital method for protecting data from those who might want to steal it.

Encryption can be used in two situations:
  1. Encryption in Transit
  2. Encryption at Rest (EAR)

Encryption in Transit

Refers to data that is encrypted when it is in transit — including from your browser to the web server and other third parties via integrations.Encrypting data in transit protects your data from man-in-the-middle-attacks.
Learn more about Encryption in Transit

Encryption at Rest

Refers to data that is encrypted when it is stored (not moving) — either on a disc, in a database, or some other form of media.In addition to encryption of data during transit, encryption of data when it is stored in the servers provides an even higher level of security. EAR protects against any possible data leak due to server compromise or unauthorized access.

Encryption is done at the application layer using the AES-256 algorithm which is a symmetric encryption algorithm and uses 128-bit blocks and 256-bit keys.The key used to convert the data from plain text to cipher text is called Data Encryption Key (DEK). The DEK is further encrypted using the KEK (Key Encryption Key), thus, providing yet another layer of security.The keys are generated and maintained by our in-house Key Management Service(KMS).
Learn more about our KMS.

What data do we encrypt in Zoho Recruit?

The following data is encrypted at rest:
  1. All file attachments and documents.
  2. PII collected through the product such as email addresses, attachments, and third-party authorization parameters.
  3. Sensitive data like integration tokens.
  4. PII data collected via custom fields.
    For more information, check out our document on how to encrypt select custom fields.

Full-disk encryption

Besides application layer encryption, full disk encryption is available in Europe (EU), India (IN), Australia (AU) and Japan (JP) datacenters.

Helpful?10
Updated: 5 months ago
Share :