What the buyer is really asking
If someone walks off with a disk, a snapshot, or a backup, can they read it? Name the algorithm, list what it covers (databases, object storage, backups), and say who controls the keys.
Other ways buyers ask it
Every one of these wants the same answer:
- “Is customer data encrypted at rest?”
- “What encryption standard do you use for stored data?”
- “Are database backups encrypted?”
- “Describe how data at rest is protected.”
Evidence to have ready
- An encryption or cryptography policy naming the algorithm (for example AES-256)
- Cloud configuration showing encryption enabled on databases, buckets, and backups
- The relevant section of a SOC 2 report or your cloud provider's attestation
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.
Related data protection questions
- What protocols and standards are used for data in transit encryption (e.g., TLS 1.2+)?
- Describe your cryptographic key management: generation, rotation, revocation, and destruction of keys.
- How do you manage and rotate encryption keys?
- Can customers supply, manage, or revoke their own encryption keys (BYOK or customer-managed keys) for the data you hold on their behalf?