Definition

Data encryption transforms readable data, or plaintext, into an unreadable encrypted format using an algorithm and a key. Only a holder of the key can decrypt it. Encryption is the fundamental control for confidentiality.

At rest and in transit

  • Encryption at rest protects stored data, whether on disk or in a backup, from unauthorised access to the medium.
  • Encryption in transit protects data travelling across a network from interception.

A sound backup practice combines both.

What matters for backup: source-side encryption

Oxibox encrypts data at source. It is encrypted before leaving the customer environment and is never transferred or stored as plaintext. This is a strong confidentiality requirement, particularly when data is stored with a hosting provider.

Encryption and incorruptibility protect different things

Encryption protects confidentiality, meaning who can read the data. On its own, it does not prevent an attacker from deleting or overwriting a backup. The software air gap and append-only write path protect the integrity and availability of restore points. With Full Cloud, data is distributed across two geo-redundant datacentres in France and is not transferred outside the European Union. An HDS option is available through an HDS-certified hosting partner.