Data Rooms Providers Find a data room
VDR glossary · Security

What is encryption at rest?

Definition

Encryption at rest: Scrambling stored files with a cryptographic key so that disks, backups and database copies are unreadable to anyone who obtains them without that key.

What encryption at rest covers in a data room

Stored files Every uploaded document and its rendered preview pages are written to disk as ciphertext.
Backups and replicas Copies kept in a second facility for recovery should carry the same protection as the primary.
Separate keys Keys live in a key management service or hardware module, apart from the data they unlock.
AES-256 Common standard The symmetric cipher most providers name in their security documentation.
Encryption at rest protects lost or stolen storage. It does not limit what a logged-in user can do; permissions handle that.
dataroomsproviders.com
Generic architecture; ask each provider how its own storage, backups and key handling are set up.

How it works in a data room

Every document you upload ends up on storage somewhere: primary disks, replicas in a second facility, nightly backups. Encryption at rest means each of those copies is written in ciphertext, typically with AES-256, and only turned back into readable pages when an authorized user opens the file through the application. The keys sit apart from the data, often in a hardware security module or a cloud key management service, and are rotated on a schedule. Some platforms add a separate key per room or per file, which narrows what a single compromised key could expose.

Why it matters in a deal

Deal files are a concentrated target: audited accounts, customer lists, patent filings and employee records in one place. If a storage volume, a backup tape or a decommissioned drive leaves the provider’s control, encryption at rest is what keeps that loss from becoming a disclosure. Security questionnaires from buyers, lenders and regulated targets almost always ask about it, and certifications such as ISO 27001 expect it to be documented. It complements, rather than replaces, encryption in transit, which protects files while they move.

Example

A mid-market private equity fund is buying a medical device maker and needs patient complaint logs in the room. Its IT team asks the shortlisted providers three questions: which algorithm protects stored files, who holds the keys, and whether backups are encrypted with the same strength. Two answer in writing within a day; the third cannot say where backup keys live and drops off the list. Our guide on data room encryption walks through the same questions.

Related terms