vStream Digital Media / ShineVR

Encryption Policy

Date: 02 June 2025
Owner: Andrés Pitt, CTO
Next Review Date: 02 June 2026
Approved by: Andrés Pitt, CTO

Definitions

TermDefinition
Companymeans vStream Digital Media
ShineVRmeans the ShineVR product developed and operated by vStream Digital Media
GDPRmeans the General Data Protection Regulation
Responsible Personmeans Andrés Pitt, CTO
Encryption at RestEncryption of data stored on disk or other storage media
Encryption in TransitEncryption of data while it moves across networks
AES-256Advanced Encryption Standard with 256-bit key length
KMSKey Management Service - Google Cloud's centralized key management system
PIIPersonally Identifiable Information

1. Policy Statement

vStream Digital Media is committed to protecting all data through comprehensive encryption measures. All ShineVR data and Company information is encrypted both at rest and in transit using industry-standard cryptographic algorithms and protocols.

This policy leverages the robust encryption capabilities of Google Cloud Platform, where all Company and ShineVR infrastructure is hosted, while defining additional encryption requirements specific to our operations.

2. Purpose

The purpose of this policy is to:

3. Scope

This policy applies to:

This policy covers:

4. Encryption Algorithms and Standards

4.1 Approved Encryption Algorithms

For Data at Rest:

For Data in Transit:

For Key Encryption:

4.2 Prohibited Algorithms

The following are explicitly prohibited due to known vulnerabilities:

5. Encryption at Rest

5.1 Google Cloud Infrastructure

5.2 ShineVR Application Data

For the trial configuration:

For other ShineVR configurations where PII may be present:

5.3 Company Data

5.4 Backup Data

5.5 Local Device Storage

6. Encryption in Transit

6.1 Network Communication

All data transmitted across networks must be encrypted using TLS:

6.2 ShineVR Application Traffic

6.3 Google Cloud Internal Traffic

6.4 Email Communication

6.5 Remote Access

6.6 Wireless Networks

7. Key Management

7.1 Google Cloud Key Management Service (KMS)

7.2 Key Storage and Protection

7.3 Key Access Control

7.4 Key Rotation

7.5 Key Lifecycle

Keys follow a defined lifecycle:

  1. Generation: Keys are generated by Google Cloud KMS using secure random number generation
  2. Active Use: Keys are used for encryption/decryption operations
  3. Rotation: New keys replace old keys according to rotation schedule
  4. Disabled: Old keys are disabled but retained for decryption of existing data
  5. Destruction: Keys are destroyed after data encrypted with them is no longer needed (follows retention schedules)

7.6 Key Backup and Recovery

8. Data Classification and Encryption Requirements

Data ClassificationEncryption at RestEncryption in TransitKey Management
PII / Sensitive Personal DataAES-256 (Mandatory)TLS 1.2+ (Mandatory)Google Cloud KMS with restricted IAM
Health Data (Pain Scores)AES-256 (Mandatory)TLS 1.2+ (Mandatory)Google Cloud KMS with restricted IAM
Company ConfidentialAES-256 (Mandatory)TLS 1.2+ (Mandatory)Google Cloud KMS
Internal DataAES-256 (Default)TLS 1.2+ (Mandatory)Google Cloud KMS
Public DataAES-256 (Default)TLS 1.2+ (Recommended)Google Cloud KMS

9. Anonymization and Pseudonymization

For ShineVR trials:

For other configurations:

10. Encryption Implementation

10.1 Google Cloud Platform Configuration

10.2 ShineVR Application Implementation

10.3 Development and Testing

11. Monitoring and Compliance

11.1 Encryption Monitoring

11.2 Audit Logging

11.3 Vulnerability Management

12. Incident Response

12.1 Encryption Failure

If encryption fails or is discovered to be misconfigured:

  1. Immediate containment: Affected systems are isolated
  2. CTO notification: Within 30 minutes of discovery
  3. Impact assessment: Determine what data was unencrypted
  4. Remediation: Enable encryption and verify configuration
  5. Data breach assessment: Determine if GDPR breach notification required

12.2 Key Compromise

If an encryption key is compromised or suspected to be compromised:

  1. Immediate key rotation: New key generated and deployed
  2. Affected data re-encryption: Data is re-encrypted with new key
  3. Access review: Review who had access to the compromised key
  4. Incident investigation: Determine how compromise occurred
  5. Monitoring: Enhanced monitoring for any use of the old key

12.3 Compromised Credentials

13. Third-Party Services

13.1 Cloud Service Providers

13.2 Other Third-Party Services

14. Data Portability and Export

When exporting data from Company or ShineVR systems:

15. Data Disposal

When data reaches end of retention period:

16. Compliance and Regulatory Requirements

This encryption policy supports compliance with:

17. Exceptions

Exceptions to this policy are rarely justified but may be considered for:

All exceptions must:

18. Roles and Responsibilities

RoleResponsibilities
CTO (Responsible Person)Policy ownership; Google Cloud KMS configuration; key management oversight; encryption monitoring; incident response; exception approval
Backend DevelopersImplement encryption in applications; secure key usage; avoid storing keys in code; report encryption issues
Product ManagerEnsure ShineVR features maintain encryption requirements; approve changes affecting encryption
All EmployeesProtect encryption keys; use encrypted connections; report encryption issues; complete security training
IT AdministratorsConfigure Google Cloud encryption settings; monitor encryption compliance; maintain audit logs

19. Training and Awareness

20. Policy Review

21. Related Policies

This policy should be read in conjunction with:

22. Contact Information

For questions regarding this policy or to report encryption-related security incidents:

Data Protection Officer / CTO — Andrés Pitt Email: andres@vstream.ie  ·  Phone: (086) 788 6570