Contentstack Launch ensures secure, encrypted connections for all deployments with built-in HTTPS and TLS support.
All deployments in Launch are served over HTTPS by default. Launch automatically provisions and manages secure SSL certificates to protect your applications. You can also bring your own certificate if needed.
Launch automatically redirects all incoming HTTP requests to HTTPS using the HTTP 308 Permanent Redirect status code.
This redirection is enforced and cannot be disabled, following industry best practices for secure content delivery. It helps protect end-user data and ensures privacy throughout the browsing experience.
Launch supports the following modern and secure versions of the Transport Layer Security (TLS) protocol to ensure data integrity and confidentiality:
To maintain broad client compatibility, Launch supports a wide set of cipher suites.
TLS 1.3:
TLS 1.2:
Note: This configuration follows Mozilla’s recommended cipher suite policy.