# Encryption at rest

> Encrypting data where it is stored — disks, databases, backups — so a stolen drive or leaked dump is ciphertext, not data.

The other half of 'encrypt everything': TLS protects data moving between systems, encryption at rest protects it sitting still — a stolen laptop, a leaked S3 bucket, a backup drive in a taxi. Modern databases and cloud storage offer it nearly free; the real question is rarely whether but who holds the keys.

Key management is where the security actually lives: keys in a managed vault (KMS), rotated, access-logged. An encrypted database whose key sits in the same repository's config file is a locked safe with the combination taped to it.

## Related terms

- https://dfieldsolutions.com/en/glossary/tls.md
- https://dfieldsolutions.com/en/glossary/secrets-management.md
- https://dfieldsolutions.com/en/glossary/gdpr.md

---

Source: https://dfieldsolutions.com/en/glossary/encryption-at-rest
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
