HomeWorkplace GlossaryEncryption at Rest and in Transit

Workplace glossary

What is Encryption at Rest and in Transit?

Encryption at rest protects data where it is stored, so a stolen disk or leaked backup is unreadable; encryption in transit protects it as it moves between browser, servers and integrations, so it cannot be read on the wire. Modern services should do both by default, typically AES-256 at rest and TLS in transit.

For buyers this is now a pass/fail checkbox rather than a differentiator: the interesting follow-ups are key management, who can decrypt, and whether backups are encrypted with the same rigour. Any workplace vendor hesitating on these has volunteered for extra scrutiny.

← Back to the Workplace Glossary