VOL IV · Nº 207FRIDAY · MAY 15 · 20261 FLAG OPEN
The RFPRoom Quarterly
Pinegate Software · published by uStack
RFP-2031 · Security

Q-2031-S01 — How is customer data encrypted at rest?

Status Approved. Reviewer: Diego Ortega.

Approved answer
Approved by Diego Ortega on May 14, 2026 5:56 PM.

All customer data is encrypted at rest using AES-256-GCM via AWS KMS. Encryption keys are managed by AWS KMS with automatic annual rotation; envelope encryption protects data keys. Customer-managed CMKs (BYOK) are available on Enterprise tier and managed through the AWS console with audit trails forwarded to the customer SIEM via CloudTrail.

Question metadata
Category: Security
Status: Approved
Drafts: 1
Reviews: 1
Draft history (1)
Every authored version, source library link, and the snippet citations attached.
  • v1Approvedmatched LIB-SEC-001May 16, 2026 5:56 PM

    All customer data is encrypted at rest using AES-256-GCM via AWS KMS. Encryption keys are managed by AWS KMS with automatic annual rotation; envelope encryption protects data keys. Customer-managed CMKs (BYOK) are available on Enterprise tier and managed through the AWS console with audit trails forwarded to the customer SIEM via CloudTrail.

    Rationale: AI-matched against LIB-SEC-001; reviewed verbatim.

Reviewer decisions (1)
Sign-offs and rationale per reviewer.
  • Diego Ortegasecurity_reviewerApprovedMay 13, 2026 5:56 PM

    Verified against trust portal documentation; no changes.

Acting as Nina Vega · VP salesswitch role →