How it works in a data room
AES is a block cipher: it transforms data in fixed 128-bit blocks using a secret key, and the same key reverses the process. The 256 refers to key length, the largest of the three sizes defined in FIPS 197. In a data room, AES-256 usually protects documents on disk and in backups, while the key itself is wrapped by a master key held in a key management system. Some providers also use it inside the cipher suites negotiated for connections, alongside the protocol that secures traffic.
Why it matters in a deal
The algorithm name has become a checkbox on security questionnaires, and almost every serious provider will tick it. That makes it a floor, not a differentiator. The more useful questions sit around it: who can access the keys, how often they rotate, whether each client or room gets its own key, and whether the cryptographic module has been validated under FIPS 140-3. A room that uses AES-256 but stores keys next to the data protects far less than the label suggests.
Example
An investment bank preparing a carve-out for a European industrial group receives a vendor questionnaire from the client’s chief information security officer. The provider’s answer reads simply AES-256. The bank pushes back and asks for the key hierarchy, rotation period and whether customer-managed keys are available. The fuller reply arrives two days later and satisfies the client. For more on what to ask, see our encryption guide and the investment banking page.