Encryption at Rest + in Transit

Comprehensive encryption architecture showing TLS 1.3 and mTLS for in-transit encryption between clients and application servers, with KMS-managed envelope encryption (DEK + KEK) protecting databases, object stores, and block storage at rest.

general · architecture diagram.

About This Architecture

Comprehensive encryption architecture showing TLS 1.3 and mTLS for in-transit encryption between clients and application servers, with KMS-managed envelope encryption (DEK + KEK) protecting databases, object stores, and block storage at rest.

Encryption at Rest + in Transit

AutoCurated TemplateSecurity
0 views0 favoritesPublic

Created by

February 8, 2026

Updated

February 13, 2026 at 5:47 PM

Type

architecture

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI