--- layout: "docs" page_title: "Security Model" sidebar_current: "docs-internals-security" --- # Security Model Consul relies on both a lightweight gossip mechanism and an RPC system to provide various features. Both of the systems have different security mechanisms that stem from their independent designs. However, the goals of Consuls security are to provide [confidentiality, integrity and authentication](http://en.wikipedia.org/wiki/Information_security). The [gossip protocol](/docs/internals/gossip.html) is powered by Serf, which uses a symmetric key, or shared secret, cryptosystem. There are more details on the security of [Serf here](http://www.serfdom.io/docs/internals/security.html). The RPC system supports using end-to-end TLS, with optional client authentication. [TLS](http://en.wikipedia.org/wiki/Transport_Layer_Security) is a widely deployed asymmetric cryptosystem, and is the foundation of security on the Internet. This means Consul communication is protected against eavesdropping, tampering, or spoofing. This makes it possible to run Consul over untrusted networks such as EC2 and other shared hosting providers.