How it plays out on a deal
Encryption at rest is now standard among serious providers, usually with AES-256. Its presence alone does not separate vendors. What does is the key management behind it: who holds the keys, how they are rotated and who inside the provider can use them.
For most deals the standard setup, with keys managed by the provider or its cloud host, is acceptable. Highly regulated clients may ask for customer-managed keys or for confirmation that backups are encrypted with the same strength as primary storage.
What to check in a review or demo
- 1Which algorithm is used and whether backups are covered too.
- 2Who manages the encryption keys and how access to them is controlled.
- 3Whether the provider's independent audit report covers its key management.
Read alongside
- Encryption in transitProtecting data while it moves between a user's device and the provider's servers, normally with TLS, so it cannot be read or altered on the way.
- AES-256The Advanced Encryption Standard with a 256-bit key, a widely used symmetric cipher that most data rooms cite for encrypting stored files.
- Customer-managed keys (CMK)An option in which the client, not the provider, controls the encryption keys for its data, often through its own cloud key service.
- SOC 2An attestation from a licensed CPA firm, under AICPA rules, that a software company's security controls are designed well (Type I) or also worked over several months (Type II).