Encryption at rest and in transit
Also known as: data encryption · TLS · encryption in transit
Encryption in transit protects data while it moves across the network; encryption at rest protects it where it is stored.
The two answer different threats. Transit protects against interception; rest protects against theft of the media or direct access to storage, once the network has been crossed.
Transit is now a given: a site served over HTTPS does it, and its absence shows immediately in a browser. Rest requires a setting, often already available from cloud providers.
Encrypting excuses nothing else. If the application decrypts to read, whoever compromises the application reads too. Encryption protects against theft of the media, not against hijacked legitimate access.
What it means for a small business
With most cloud providers, encryption at rest is a box already ticked. The right question is not to build it but to check it is on and be able to say so.
Related terms
So what actually applies to you?
A definition tells you what a term means, not what your organization must do. The assessment answers the second question — free, no credit card.
Updated September 1, 2026 · Educational definition; not legal advice.