Data encryption | Vani

Encryption in Vani

Encryption is used to protect sensitive information by converting readable data into an unreadable format. Only authorized systems with the appropriate keys can decrypt and access the original data. This process helps ensure that information remains secure from unauthorized access or interception.

In Vani, encryption is applied in two key scenarios:

  • Encryption in transit

  • Encryption at rest (EAR)

Encryption in transit  

Encryption in transit refers to data that's protected while it's being transferred between systems, such as between your browser and Vani’s servers, or between Vani and other services through integrations.

Encrypting data during transmission helps prevent attacks such as man-in-the-middle attacks, where malicious actors attempt to intercept or alter data while it's moving across networks.

Learn more about encryption in transit.

Encryption at rest  

Encryption at rest refers to data that's encrypted while it's stored on servers, whether on disks, databases, or other storage media.

By encrypting stored data in addition to encrypting data during transit, Vani provides an additional layer of protection against risks such as server compromise, unauthorized access, or potential data leaks.

Encryption is implemented at the application layer using the AES-256 algorithm. AES-256 is a symmetric encryption standard that uses 128-bit blocks and 256-bit keys.

The key used to convert plaintext data into encrypted data is called the Data Encryption Key (DEK). The DEK itself is encrypted using a Key Encryption Key (KEK) to add another layer of security.

All encryption keys are generated and managed through Zoho’s in-house Key Management Service (KMS).

Learn more about our KMS.

What data does Vani encrypt?  

Vani encrypts sensitive application data as well as personally identifiable information (PII), such as email addresses and IP addresses.

Data stored or processed within Vani is protected through encryption mechanisms to ensure secure storage and handling.

Learn more about encryption and our KMS.

Full disk encryption  

In addition to application-layer encryption, full disk encryption is implemented in Zoho’s EU (Europe), IN (India), and AU (Australia) data centers to provide additional protection for stored data.
    • Related Articles

    • HIPAA compliance with Vani

      The Health Insurance Portability and Accountability Act, HIPAA (including the Privacy Rule, Security Rule, Breach notification Rule, and Health Information Technology for Economic and Clinical Health Act), requires Covered Entities and Business ...
    • What is Vani MCP

      What is Vani MCP Vani MCP lets supported AI assistants and MCP clients connect securely to your Vani workspace, understand your projects and documents, and help you perform actions in Vani from a conversation. MCP stands for Model Context Protocol. ...
    • Troubleshoot Vani MCP in Claude

      Claude says it cannot reach the MCP server Check that you entered the correct Vani MCP server URL and that it ends with /mcp. Example: https://app.vanihq.com/mcp. Do not use a private, local, staging, or VPN-only URL unless Vani support has asked you ...
    • Use Vani MCP in Claude

      Get started After setup, enable the Vani connector in a Claude conversation, then ask Claude for help with Vani work. Example prompts: Find Vani Spaces about Q4 launch planning and summarize what each Space contains. Search my team for comments ...
    • Set up Vani MCP in Claude

      Before you begin, you need: A Vani account. Access to the Vani team, Space, or Zone you want the AI assistant to work with. A Claude plan that supports connectors. The Vani MCP server URL for your Vani data center (see below). Vani MCP server URLs ...