---
title: Encryption
description: Details on how Langfuse Cloud encrypts data both in transit and at rest.
---

# Encryption

Langfuse employs robust encryption methods to protect your data both while it's being transferred and while it's stored.

This page describes the encryption practices for Langfuse Cloud. For self-hosted deployments, please refer to the [Self-hosting Guide](/self-hosting/configuration/encryption).

## Encryption in Transit

All data transferred between your applications, the Langfuse SDKs, and the Langfuse server is encrypted using **TLS 1.2 (Transport Layer Security)**. This ensures that data is protected from eavesdropping or tampering during transmission.

## Encryption at Rest

Data stored within the Langfuse infrastructure is encrypted at rest using **AES-256**, a strong industry-standard encryption algorithm.

This applies to data stored in:

| Service             | Encryption Standard |
| ------------------- | ------------------- |
| Elasticache (Redis) | AES-256             |
| Aurora (Postgres)   | AES-256             |
| Clickhouse          | AES-256             |
| S3 / Blob Storage   | AES-256             |

## Contact

For questions regarding encryption practices, please [talk to us](/talk-to-us).

<!-- agent-instructions -->

---

## Agent Instructions

This page is part of the [Langfuse](https://langfuse.com) documentation, published as plain Markdown for AI agents. Every page is available as Markdown by appending `.md` to its URL, or by sending an `Accept: text/markdown` header. This page: `https://langfuse.com/security/encryption.md`.

### Querying these docs

If the answer is not on this page, query the documentation instead of guessing:

- **Semantic search** across all Langfuse docs, returning an answer with the relevant pages and excerpts. Ask a specific, self-contained question:

  ```bash
  curl -sG "https://langfuse.com/api/search-docs" --data-urlencode "query=How do I trace a LangGraph agent?"
  ```

- **Index of every page**: <https://langfuse.com/llms.txt>, with per-section indexes [llms-docs.txt](https://langfuse.com/llms-docs.txt), [llms-integrations.txt](https://langfuse.com/llms-integrations.txt), and [llms-self-hosting.txt](https://langfuse.com/llms-self-hosting.txt).

### Before writing Langfuse code

- **Install the [Langfuse Agent Skill](https://langfuse.com/docs/api-and-data-platform/features/agent-skill).** It encodes Langfuse's own best practices for instrumentation, prompt management, and evaluation, and materially improves results.
- **Read [What does a good trace look like?](https://langfuse.com/docs/observability/best-practices.md)** before instrumenting an application.
- **Verify endpoints, parameters, and response fields** against the [API reference](https://api.reference.langfuse.com) instead of inferring them from code examples.
- **Use the [Langfuse CLI](https://langfuse.com/docs/api-and-data-platform/features/cli)** (`npx langfuse-cli api <resource> <action>`) to read or write traces, prompts, datasets, and scores from the terminal.

Found an error in these docs? Please open an issue at <https://github.com/langfuse/langfuse-docs/issues>.
