Data encryption
Data transfer
All off-premises network protocols are TLS 1.3 encrypted:
- WSS (Web Socket Secure), 
- RTMPS (Real-Time Messaging Protocol Secure) 
- WebRTC (Web Real-Time Communication) 
- HTTPS (Hypertext Transfer Protocol Secure) 
Data storage
Optionally, the cloud storage can be encrypted – a feature provided by the cloud storage providers.
VXG uses AWS that meets high industry standards for data security, disaster recovery, physical and privacy, including ISO 27001, SSAE16/ISAE 3402 Type II: SOC 2, and SSAE16/ISAE 3402 Type II: SOC 3 certifications. See AWS Cloud Security for more information.
In the case of AWS S3 storage, AWS offers several options for data encryption. See https://docs.aws.amazon.com/AmazonS3/latest/userguide/serv-side-encryption.html for more information.
Camera connection
All Internet traffic is TLS encrypted, except in the case of port forwarding which is strongly not recommended.
Below are diagrams showing security configurations depending on the connectivity method.
Direct to Cloud
Uplink module running on a camera:

Using Gateway
Uplink module running on an on-prem device

Direct ONVIF
Connection over VPN to a VPN IP address of a camera.

Connection using port forwarding and using public IP address and port of a camera

The last method is not recommended