انتقل إلى المحتوى الرئيسي
DocumentMS

Glossary

Encryption at rest

Also called: data at rest encryption

Encryption at rest protects stored data by encrypting it on disk, so that physical access to the storage medium does not yield readable content. It is table stakes for any document system, and the question worth asking is not whether it exists but who controls the keys.

Encryption at rest explained

What it protects against

A stolen disk, a decommissioned drive that was not wiped, a misconfigured storage bucket exposed to the internet, and an attacker who obtains raw storage without obtaining application credentials. In each case the encrypted bytes are useless without the key.

What it does not protect against

A compromised authorised account. If an attacker signs in as a legitimate user, the application decrypts content for them exactly as it would for the real user — which is why encryption is a necessary control and not a sufficient one, and why two-factor authentication and access review matter alongside it.

It also does nothing about an over-permissioned internal user, which is a more common cause of inappropriate access than any external attack.

Who holds the keys

The question that distinguishes vendors. Provider-managed keys are the default and are adequate for most buyers. Customer-managed keys, held in your own key management service, mean the vendor cannot decrypt content without a key you can revoke — which is a materially stronger position and is often available only where you supply the storage backend.

Encryption in transit is separate

TLS protects data moving between systems. Both are needed, and a vendor answering a question about one with an answer about the other is worth pressing.

FAQ

Encryption at rest: common questions

Is AES-256 necessary, or is AES-128 enough?

Both are considered secure against brute force. AES-256 is what procurement questionnaires expect, so it is usually specified for that reason rather than a practical cryptographic one.

Can the vendor read our documents?

With provider-managed keys, technically yes, subject to their internal controls. With customer-managed keys in your own key service, no — which is why the key question is the one worth asking.

جلسة من ثلاثين دقيقة مع مهندس حلول، على بنية مجلدات وسلسلة اعتماد تشبه ما لديك — لا بيئة عرض عامة.