Default transport
Apex terminates HTTPS at the edge and maintains encrypted transport for request handling. Application teams do not need to distribute certificate files across regions.
Certificate lifecycle
Domain verification precedes certificate issuance. Renewal is handled by the platform and certificate state is visible from the project domain view.
Application responsibility
Encryption in transit does not replace application authentication, authorization, or sensitive-data handling.
Review the full security model
See the complete set of security controls and enterprise requirements.
