LNC Nexus · Trust Center← Back to LNC Nexus
Trust Center document

Encryption Policy

Public security and assurance reference

POL-7: Encryption Policy

Purpose

This policy establishes the requirements for encrypting data to protect its confidentiality and integrity. It ensures that legal-medical knowledge and analysis data is secured against unauthorized access during storage and transmission.

Scope

This policy applies to all data processed, stored, or transmitted by LNC Nexus hosted, private, or self-managed deployments. It covers regulated data, proprietary information, and public data.

Policy Statements

Data at rest and in transit shall be encrypted using approved algorithms and key lengths. Encryption keys must be managed securely and rotated periodically. In self-managed deployments, customers are responsible for implementing encryption; LNC Nexus provides the mechanisms but not the enforcement. Regulated data handling requires end-to-end encryption. No data shall be transmitted or stored unencrypted without explicit justification.

Roles and Responsibilities

The Security Team defines encryption standards and monitors compliance. System administrators implement encryption measures and manage keys. Users ensure data is encrypted before transmission. The Legal Team reviews encryption requirements for regulatory compliance.

Evidence and Review

Encryption logs, key management records, and audit reports serve as evidence of compliance. The Security Team conducts periodic reviews of encryption practices and investigates anomalies. Deployment-specific configurations are treated as controlled material.

Exceptions

Exceptions to this policy require written approval from the Security & Compliance owner or delegated risk owner and must be documented with a risk acceptance statement. Exceptions are valid only for a defined period and must be re-evaluated before expiration.

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination, and legal prosecution where applicable. Data access may be suspended immediately upon detection of a violation.

POL-5 (Data Classification Policy), POL-6 (Data Retention and Disposal Policy), POL-1 (Access Control Policy).

Revision History

VersionStatusChange
1.0Draft for approvalInitial framework draft