Inside Pega Enterprise Infrastructure: Security and Encryption / Data-at-Rest Encryption

The Blueprint dashboard includes a dedicated tab for Enterprise Infrastructure capabilities, and this post is part of a series of posts that explore each capability in detail.

Pega Cloud uses data-at-rest encryption (DARE) in all Pega Cloud environments to help secure application data and support industry-standard security requirements.

:white_check_mark: What it means

Data at rest means content that the cloud service saves on a hard drive. In Pega Cloud, this saved application data is encrypted across Pega Cloud environments.

  • DARE stands for data-at-rest encryption.

  • It applies to all Pega Cloud environments described in the documentation.

  • Encryption of data at rest is implemented for all sandbox and production environments.

:white_check_mark: What it does

  • Helps secure application data stored by Pega Cloud.

  • Helps support industry-standard security requirements.

  • Encrypts client data stored in volumes, databases, and object storage buckets.

  • Uses 256-bit encryption for client data stored in those locations.

:white_check_mark: How it works

:white_check_mark: What to remember

  • Pega Cloud documents DARE as available across all Pega Cloud environments.

  • The documentation explicitly includes all sandbox and production environments.

  • The documented encrypted storage areas are volumes, databases, and object storage buckets.

  • The documented encryption strength is 256-bit encryption.

  • The documented key management approach includes regular key rotation and secure storage in a FIPS 140-2 compliant KMS.

:open_book: Technical documentation: Data-at-rest encryption in Pega Cloud – docs.pega.com