TLS 1.3 for API traffic, AT-TLS on z/OS, IPSec for MQ channels. 2. **Encrypt everything at rest** — DFSMS dataset encryption on z/OS, cloud KMS encryption; keys never cross the platform boundary. 3. **Authenticate every request** — every API call carries a token; every MQ message carries sender iden