Default transport

Apex terminates HTTPS at the edge and maintains encrypted transport for request handling. Application teams do not need to distribute certificate files across regions.

Certificate lifecycle

Domain verification precedes certificate issuance. Renewal is handled by the platform and certificate state is visible from the project domain view.

Application responsibility

Encryption in transit does not replace application authentication, authorization, or sensitive-data handling.

Review the full security model

See the complete set of security controls and enterprise requirements.

Back to Security