How to Answer Encryption-at-Rest Questions

Your customer asked: “Is customer data encrypted at rest?”

The short answer

Encryption at rest concerns stored data. Before answering, identify where customer information is stored and confirm which storage systems, databases, devices, and backups are actually encrypted.

Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.

What the customer is really asking

Understand the question before you answer it.

The customer is trying to understand whether stored information remains protected if storage media, a database, a device, or another storage layer is accessed improperly. Scope matters because a company may encrypt production databases but handle exports or backups differently.

How to answer accurately

Start with the version that matches reality.

1

If stored customer data is encrypted

Describe the storage scope you can support. If you name an algorithm, key-management system, or cloud feature, verify the exact configuration first.

2

If coverage is partial

State where encryption applies and where it does not rather than treating one encrypted system as proof for all stored data.

3

If a cloud provider handles encryption

You may describe the provider-supported configuration if it is actually enabled for your environment. Provider capability alone is not your company configuration.

A useful answer structure

Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.

Evidence that may help

These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.

  • Database or storage encryption settings
  • Device encryption status
  • Cloud provider configuration
  • Backup encryption configuration

What not to say

  • That all customer data is encrypted because one primary database is encrypted.
  • A cryptographic standard you have not verified.
  • That provider availability equals enabled configuration.

How Oredra handles this

Answer it once. Keep the truth behind the answer.

Oredra can maintain the exact storage scope behind the answer and flag future questions whose wording is broader than the approved fact.

Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.

Authoritative references

Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.

Related questionnaire questions