[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-encryption-at-rest::en":3,"gloss-cluster-encryption-at-rest::en":20,"gloss-next-encryption-at-rest::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"encryption-at-rest","security","Encryption at Rest","Encryption at rest means the data your app stores — in databases, object storage, backups, and disks — is encrypted on disk, so someone who obtains the raw storage media or a stolen backup file can't read it. It's distinct from encryption in transit (TLS), which protects data moving over the network. For SaaS builders, encryption at rest is close to free today: managed databases and stores like AWS RDS, S3, and Google Cloud enable AES-256 disk encryption with a checkbox, and it's an expected \"yes\" on every security questionnaire and SOC 2 audit. Practical note: default at-rest encryption protects against stolen hardware, not against an attacker who already has valid database access — those queries are decrypted transparently. For higher-sensitivity fields (tokens, PII), layer application-level or field-level encryption on top, and manage keys in a KMS with rotation rather than hardcoding them. See also BYOK for customer-controlled keys.","Encryption at rest keeps stored data — databases, object storage, backups, disks — unreadable to anyone who gets the raw media, unlike TLS which guards transit.",null,[11,14,17],{"slug":12,"name":13},"byok","Bring Your Own Key (BYOK)",{"slug":15,"name":16},"pii","Personally Identifiable Information (PII)",{"slug":18,"name":19},"soc-2","SOC 2",[21,25,29,33,36,39,40,43,46,49,52,55],{"slug":22,"category":5,"name":23,"updated_at":24},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":26,"category":5,"name":27,"updated_at":28},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":30,"category":5,"name":31,"updated_at":32},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":34,"category":5,"name":35,"updated_at":32},"bridge-letter","Bridge Letter",{"slug":37,"category":5,"name":38,"updated_at":32},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":12,"category":5,"name":13,"updated_at":24},{"slug":41,"category":5,"name":42,"updated_at":32},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":44,"category":5,"name":45,"updated_at":28},"data-classification","Data Classification",{"slug":47,"category":5,"name":48,"updated_at":32},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":50,"category":5,"name":51,"updated_at":32},"data-minimization","Data Minimization",{"slug":53,"category":5,"name":54,"updated_at":32},"data-poisoning","Data Poisoning",{"slug":56,"category":5,"name":57,"updated_at":32},"data-processing-agreement","Data Processing Agreement (DPA)"]