Last reviewed Sep 16, 2025 (11 months ago). Reuse count: 28.
All customer data is encrypted at rest using AES-256-GCM via AWS KMS. Encryption keys are managed by AWS KMS with automatic annual rotation; envelope encryption protects data keys. Customer-managed CMKs (BYOK) are available on Enterprise tier and managed through the AWS console with audit trails forwarded to the customer SIEM via CloudTrail.
Source: Encryption-at-rest architecture