Data in transit Transport protection, certificate validation and mTLS where the integration profile requires it.
Cryptographic keys Key separation, lifecycle, rotation and revocation within HSM/KMS boundaries where applicable.
Integration secrets Client secrets, API credentials and connector credentials are governed separately.