Definition
Data encryption transforms readable data, or plaintext, into an unreadable encrypted format using an algorithm and a key. Only a holder of the key can decrypt it. Encryption is the fundamental control for confidentiality.
At rest and in transit
- Encryption at rest protects stored data, whether on disk or in a backup, from unauthorised access to the medium.
- Encryption in transit protects data travelling across a network from interception.
A sound backup practice combines both.
What matters for backup: source-side encryption
Oxibox encrypts data at source. It is encrypted before leaving the customer environment and is never transferred or stored as plaintext. This is a strong confidentiality requirement, particularly when data is stored with a hosting provider.
Encryption and incorruptibility protect different things
Encryption protects confidentiality, meaning who can read the data. On its own, it does not prevent an attacker from deleting or overwriting a backup. The software air gap and append-only write path protect the integrity and availability of restore points. With Full Cloud, data is distributed across two geo-redundant datacentres in France and is not transferred outside the European Union. An HDS option is available through an HDS-certified hosting partner.
