VOL IV · Nº 207FRIDAY · MAY 15 · 20261 FLAG OPEN
The RFPRoom Quarterly
Pinegate Software · published by uStack
Library · Security

LIB-SEC-001 — How is customer data encrypted at rest?

Last reviewed Sep 16, 2025 (11 months ago). Reuse count: 28.

Answer
Canonical answer maintained by the knowledge admin. Used by AI drafting to seed RFP draft v1.

All customer data is encrypted at rest using AES-256-GCM via AWS KMS. Encryption keys are managed by AWS KMS with automatic annual rotation; envelope encryption protects data keys. Customer-managed CMKs (BYOK) are available on Enterprise tier and managed through the AWS console with audit trails forwarded to the customer SIEM via CloudTrail.

Source: Encryption-at-rest architecture

Metadata
Category
Security
Status
Approved
Freshness
Aging
Freshness policy
12 months
Last reviewed
Sep 16, 2025
Author
Rachel Murphy
Reuse count
28
Times drafted from
1
Used by drafts (1)
RFP questions that drafted from this library entry.
Acting as Nina Vega · VP salesswitch role →