Source
Encryption & access control — found from sitemap — Mattermost
Checked for Mattermost on 1 Oct 2026
- Page
- https://docs.mattermost.com/deployment-guide/encryption-options
- Checked
- 1 Oct 2026, 15:36 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:b585c557c3b9bd61a52eb1d9afb614289fa879c22e26b428f19ca530bdcc4719
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Encryption plans Report an error
“Available on Entry, Professional, Enterprise, and Enterprise Advanced plans”
-
Encryption types Report an error
“Mattermost provides encryption-in-transit and encryption-at-rest capabilities.”
-
Tls encryption Report an error
“Mattermost supports TLS encryption including AES-256 with 2048-bit RSA on all data transmissions between Mattermost client applications and the Mattermost server.”
-
Ldap tls Report an error
“Connections to Active Directory/LDAP can optionally be secured with TLS or stunnel.”
-
Calls encryption Report an error
“DTLS v1.2 (mandatory): Used for initial key exchange. Supports TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 and TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA algorithms.”
-
Gossip encryption Report an error
“In a High Availability mode, Mattermost supports encryption of cluster data in-transit when using the gossip protocol”
-
Gossip encryption default Report an error
“From Mattermost v10.11, gossip encryption is enabled by default for new deployments while existing deployments maintain their current configuration.”
-
Gossip encryption cipher Report an error
“The encryption uses AES-256 by default, and it is not configurable.”
-
At rest database Report an error
“Encryption-at-rest is available for messages via hardware and software disk encryption solutions applied to the Mattermost database, which resides on its own server within your infrastructure.”
-
No database internal encryption Report an error
“To enable end user search and compliance reporting of message histories, Mattermost does not offer encryption within the database.”
-
At rest disk methods Report an error
“Full-disk encryption methods such as LUKS (Linux), BitLocker (Windows), or database-specific solutions like Transparent Data Encryption (TDE) can be employed. Integration with external encrypted storage systems is supported.”
-
At rest files Report an error
“Additionally, encryption-at-rest is available for files stored via hardware and software disk encryption solutions applied to the server used for local/network storage or S3-compatible storage.”
-
S3 server side encryption Report an error
“For Amazon’s proprietary S3 system, encryption-at-rest is available via server-side encryption with Amazon S3-managed keys in Mattermost enterprise-badge.”
-
SAML encryption Report an error
“SAML assertion encryption is configured alongside the rest of your identity provider settings rather than at the infrastructure layer.”
-
GDPR encryption note Report an error
“Encryption is not required for GDPR, although it can be used as an additional safeguard against data breach.”
Scores citing this record
- The Compliance Counsel Encryption & access control
- The Platform Engineer Encryption & access control
- The Security Officer Encryption & access control
- The Skeptic Encryption & access control
- The Team Lead Encryption & access control
- The Works Council Advocate Encryption & access control