Status Approved. Reviewer: Diego Ortega.
All customer data is encrypted at rest using AES-256-GCM via AWS KMS. Encryption keys are managed by AWS KMS with automatic annual rotation; envelope encryption protects data keys. Customer-managed CMKs (BYOK) are available on Enterprise tier and managed through the AWS console with audit trails forwarded to the customer SIEM via CloudTrail.
All customer data is encrypted at rest using AES-256-GCM via AWS KMS. Encryption keys are managed by AWS KMS with automatic annual rotation; envelope encryption protects data keys. Customer-managed CMKs (BYOK) are available on Enterprise tier and managed through the AWS console with audit trails forwarded to the customer SIEM via CloudTrail.
Rationale: AI-matched against LIB-SEC-001; reviewed verbatim.
Verified against trust portal documentation; no changes.