In a world increasingly reliant on digital infrastructure, protecting sensitive information is more critical than ever. Data is vulnerable at different stages—when stored, when moving between systems, and even when being processed (often referred to as data in use, active data, or operational data).
Unfortunately, compliance is typically vague when it comes to data encryption requirements for data at rest and in transit, and there is little mention of encrypting data in use.
There is also a lot of confusion distinguishing between data in transit and data in use. Many security leaders see these states as being one in the same. In reality, they are vastly different and not recognizing the difference will leave an operation’s most valuable data fully exposed to threat.
This blog post breaks down the three primary types of data encryption: Data at Rest, Data in Transit, and Data in Use. We’ll explore why each is essential, how they differ, and provide real-world examples to understand their roles in safeguarding information.
🔒 Data at Rest
Summary: Data stored on a physical or cloud storage medium—such as databases, hard drives, or backups. Data at rest is only effective while the target data is in a static, or at rest state. In order to use, or perform any calculations upon the data it must be decrypted and moved to a plaintext storage environment such as cache, RAM, hard drive, or processing database. Once the processing is completed, best practice calls for that data to be re-encrypted for storage. This process requires expertise and is very time-consuming. It also exposes the data to threat while it is decrypted for processing. When using a cloud provider for encryption at rest services, the process of Encryption -> Decryption -> Processing -> Re-encryption can be very costly to the organization. All of this impacts practical adoption in support of today’s on-demand data utilization requirements. For example: Encryption of data at rest is not designed to support new GenAI/AI use cases.
Goal: Prevent unauthorized access in the event the storage device is compromised.
Common Methods: Full-disk encryption (FDE), file-level encryption, database encryption.
Not sure which option is right for you? see SAFE pricing for your organization Choose the SAFE deployment model that fits your security requirements.
🚀 Data in Transit
Summary: Data actively moving through networks—between devices, data centers, or users. Data is commonly in transit through both internal and external networks. The data is encrypted, then contained within a transport vehicle to be sent from one point to another. Or, the transport method is encrypted (i.e. a Virtual Private Network (VPN), HTTPS, TLS, or Secure FTP) offering a secure conduit for transmitting the data. Like Encryption of data at rest, the data itself is static, meaning it is not in use and no changes or calculations are being performed upon the data. In order to query or perform tasks upon encryption of data in transit, the same process as encryption of data at rest must be performed—Encryption-> Decryption -> Processing -> Re-encryption
Goal: Protect data from eavesdropping, interception, or man-in-the-middle attacks during transmission.
Common Methods: TLS (Transport Layer Security), HTTPS, VPNs, Secure FTP, and Encrypted Email or Encrypted Files Attached to Email.
⚙️ Data in Use
Summary: Data being actively processed (Calculations are being performed such as common Create, Read, Update, and Delete (CRUD) functions) in memory or by an application—e.g., data in RAM, Cache, Processing Servers, or within CPU registers. Unlike the static data secured by encryption of data at rest or in transit technologies. Encryption of data in use is used to secure the most valuable and active data within the organization wile that data remains fully encrypted—No decryption necessary to support the operational application (or query) layer.
Goal: Secure data while it is most valuable and vulnerable—In Use supporting key operational applications. Addresses the largest (and growing), most costly gap in data security—Billions of plaintext records are compromised annually requiring minimal threat-actor effort. Threat-actors are in the network, Encryption of Data-in-Use assures that the critical operational data is the most secure.
Common Methods: Searchable Symmetric Encryption (SSE) for on-demand data, Homomorphic encryption (HE), Confidential Computing or Trusted Execution Environments (TEEs), Secure Enclaves (Intel SGX, AMD SEV).
📊 Comparison Table
| Feature | Data at Rest | Data in Transit | Data in Use |
| State of Data | Stored | Being transmitted | Actively processed |
| Primary Risk | Theft from storage media | Interception over network | Side-channel attacks, memory scraping, Ransomware, Data Theft |
| Encryption Examples | Paperclip SAFE®, AES, FDE, BitLocker, EFS | TLS, SSL, HTTPS, IPSec | Paperclip SAFE®, Homomorphic Encryption, Intel SGX, AMD SEV |
| Performance Impact | Low to moderate | Low | Low with Paperclip SAFE®, Moderate to high with Homomorphic and Confidential Computing |
| Common Tools | Paperclip SAFE®, VeraCrypt, AWS KMS, Azure Disk Encrypt | OpenSSL, TLS/SSL, SSH, VPNs | Paperclip SAFE®, Microsoft Azure Confidential Computing, IBM Cloud Hyper Protect |
| Use Environment | Local servers, cloud storage | Internet, internal networks | Cloud Computation, Financial Services, Healthcare, Privacy, IoT, Banking, GenAI/AI, PCI, Telecommunications, Billing, Human Resources, Payroll, Active Archives, Resiliency, Third-Party Access |
🛡️ Why Each Is Necessary
✔️ Data at Rest: Ensures stolen or hacked static data storage remains unreadable without keys.
✔️ Data in Transit: Secures static data between endpoints, preventing interception or tampering.
✔️ Data in Use: Protects sensitive data while in active use, addressing RAM, Processing Server, and CPU vulnerabilities.
🧪 Use Case Examples
🔒 Data at Rest:
- Healthcare providers encrypt patient records to comply with HIPAA.
- Financial institutions use disk encryption for transaction logs.
- Cloud services (AWS, Azure) encrypt stored data automatically.
🚀 Data in Transit:
- E-commerce uses HTTPS to protect checkout data.
- Remote teams use VPNs for secure communication.
- IoT devices send encrypted data to central servers.
⚙️ Data in Use:
- Ensure Privacy for secure operational data usage.
- GenAI/AI critical data controls.
- Secure sensitive data in defense and government sectors.
- Control exposure to private, critical, or valuable data during ransomware attack.
- Meet and exceed current and future data security and data access compliance requirements.
- Prepare for Post-Quantum Readiness (PQR).
- Support operational resiliency demands.
- Apply Zero Trust to Operational Data Supply-Chain.
