# Security of Mender Artifacts containing sensitive information

**URL:** <https://hub.mender.io/t/security-of-mender-artifacts-containing-sensitive-information/6064>\
**Category:** Update Modules\
**Tags:** mender-artifact\
**Created:** [August 2, 2023, 6:05am UTC](https://hub.mender.io/t/security-of-mender-artifacts-containing-sensitive-information/6064 "2023-08-02T06:05:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![schen](https://avatars.discourse-cdn.com/v4/letter/s/3ec8ea/32.png) [@schen](https://hub.mender.io/u/schen)\
**Post date:** [August 2, 2023, 6:05am UTC](https://hub.mender.io/t/security-of-mender-artifacts-containing-sensitive-information/6064/1 "2023-08-02T06:05:00Z")

</div>

I would like to know how secure it is to have a Mender Artifact with a file containing sensitive information in the payload. For my use case, the Artifact would be uploaded to Hosted Mender and deployed to a remote PC. Is it possible to obtain the sensitive information by interception?

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [August 2, 2023, 7:35am UTC](https://hub.mender.io/t/security-of-mender-artifacts-containing-sensitive-information/6064/2 "2023-08-02T07:35:10Z")

</div>

Hello @schen,

Thanks for reaching out! The transfer of the Artifact in itself is authenticated and encrypted as HTTPS is being used. However, if the remote PC (physically) or the Mender dashboard (artifact download) can be accessed by people who are not meant to see that sensitive data, we recommend additional measures.

Greetz,  
Josef
