Skip to content
Find my data room
Data room terms / Document protection

Encryption at rest

The short version

Scrambling stored files, backups included, so that anyone who walks off with a disk or a backup set gets unreadable data unless they also hold the keys.

How it plays out on a deal

Encryption at rest is now standard among serious providers, usually with AES-256. Its presence alone does not separate vendors. What does is the key management behind it: who holds the keys, how they are rotated and who inside the provider can use them.

For most deals the standard setup, with keys managed by the provider or its cloud host, is acceptable. Highly regulated clients may ask for customer-managed keys or for confirmation that backups are encrypted with the same strength as primary storage.

What to check in a review or demo

  1. 1Which algorithm is used and whether backups are covered too.
  2. 2Who manages the encryption keys and how access to them is controlled.
  3. 3Whether the provider's independent audit report covers its key management.

Read alongside

Where this comes up on Data Room Review