How to Answer Encryption-at-Rest Questions
Your customer asked: “Is customer data encrypted at rest?”
The short answer
Encryption at rest concerns stored data. Before answering, identify where customer information is stored and confirm which storage systems, databases, devices, and backups are actually encrypted.
Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.
What the customer is really asking
Understand the question before you answer it.
The customer is trying to understand whether stored information remains protected if storage media, a database, a device, or another storage layer is accessed improperly. Scope matters because a company may encrypt production databases but handle exports or backups differently.
How to answer accurately
Start with the version that matches reality.
If stored customer data is encrypted
Describe the storage scope you can support. If you name an algorithm, key-management system, or cloud feature, verify the exact configuration first.
If coverage is partial
State where encryption applies and where it does not rather than treating one encrypted system as proof for all stored data.
If a cloud provider handles encryption
You may describe the provider-supported configuration if it is actually enabled for your environment. Provider capability alone is not your company configuration.
A useful answer structure
Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.
Evidence that may help
These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.
- Database or storage encryption settings
- Device encryption status
- Cloud provider configuration
- Backup encryption configuration
What not to say
- That all customer data is encrypted because one primary database is encrypted.
- A cryptographic standard you have not verified.
- That provider availability equals enabled configuration.
How Oredra handles this
Answer it once. Keep the truth behind the answer.
Oredra can maintain the exact storage scope behind the answer and flag future questions whose wording is broader than the approved fact.
Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.
Authoritative references
Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.
Related questionnaire questions
Is customer data encrypted in transit?
The question is asking whether information is protected while moving between systems, users, or services. Verify the actual protocols and the scope of the data flows before answering. Do not assume that using a modern cloud platform means every transmission path is covered.
How long do you retain customer data, and how is it deleted?
Describe the actual retention and deletion practice for the data in scope. Be especially careful with fixed timelines, backups, legal or contractual retention, and copies held by subprocessors because those details can make a simple answer inaccurate.