DataSunrise Achieves AWS Data & Analytics Competency. Learn more →

Part ofProtection and Enforcement

PostgreSQL Encryption at Rest

Selective Encryption with Transparent Application Access

Encrypt selected PostgreSQL and Aurora PostgreSQL columns or complete tables while authorized applications continue to work through DataSunrise.

  • Selected Columns or Full Tables
  • Transparent Application Access
  • DataSunrise, CyberArk, or AWS KMS Keys

Protect stored data without rewriting applications

DataSunrise protects sensitive PostgreSQL and Aurora PostgreSQL data in storage while authorized applications continue to use it through the DataSunrise proxy. Teams can encrypt selected columns or complete tables without rewriting client applications.

The workflow combines PostgreSQL pgcrypto with AES-128, DataSunrise query rewriting, and managed key exchange. Keys can be managed inside DataSunrise or through CyberArk or AWS KMS.

Encrypted in storage, clear for authorized applications

DataSunrise manages the protected access path without requiring changes to client applications.

Application

  • Connects through DataSunrise
  • Uses normal PostgreSQL operations

DataSunrise protected access path

  • Rewrites the required queries
  • Coordinates managed key exchange
  • Returns authorized clear values

Encrypted PostgreSQL data

  • Selected columns or full tables
  • pgcrypto with AES-128
  • Stored values remain encrypted
Direct database access sees encrypted stored values. Applications that need clear values connect through DataSunrise.

Explore PostgreSQL Encryption at Rest

1 / 4

Choose What to Protect

Match the encryption scope to the data that needs protection.

  • Selected columns. Encrypt the fields that carry personal, financial, regulated, or commercially sensitive values.
  • Complete tables. Protect the full table when the entire dataset needs encryption.
  • Column-specific keys. Use a separate key for a selected column when stronger separation is required.

The stored representation remains encrypted while authorized applications continue to query the data through DataSunrise.

Set Up the Encryption Workflow

Connect a PostgreSQL or Aurora PostgreSQL instance, select the columns or tables to protect, and choose where encryption keys will be managed. DataSunrise then creates the encrypted representation and prepares the protected query path.

Once the task is active, authorized applications connect through DataSunrise and continue using their normal PostgreSQL operations.

Manage Keys Your Way

Choose the key-management option that fits your security architecture.

  • DataSunrise internal store. Keep key management inside the DataSunrise environment for a direct, platform-managed setup.
  • CyberArk. Use a configured CyberArk safe, folder, and object when CyberArk already manages organizational secrets.
  • AWS KMS. Protect generated keys with AWS KMS for KMS-backed governance in AWS deployments.

Keep Application Access Transparent

Applications connect through DataSunrise and continue using normal PostgreSQL operations. The proxy rewrites the required queries and coordinates key exchange so authorized sessions receive clear values while the stored representation remains encrypted.

Direct database access sees the encrypted stored values. Applications that need transparent access use the managed DataSunrise path.

FAQ

Frequently Asked Questions

Which databases support Encryption at Rest?

The DataSunrise Encryption at Rest workflow supports PostgreSQL and Amazon Aurora PostgreSQL.

Can I encrypt individual columns or complete tables?

Yes. Teams can protect selected columns or apply encryption across a complete table.

Do applications need to be rewritten?

No client-side rewrite is required. Authorized applications connect through DataSunrise, which manages query rewriting and key exchange for transparent access.

How are encryption keys managed?

Keys can be managed in the DataSunrise internal store, CyberArk, or AWS KMS.

How is Encryption at Rest different from TLS?

Encryption at Rest protects stored PostgreSQL values. TLS protects data while it travels across the network. Many deployments use both controls together.

How does this work with monitoring, masking, and firewall controls?

Database Activity Monitoring records access and operations, Dynamic Data Masking controls how clear values appear in live results, and Database Firewall can block risky operations. Encryption at Rest protects the stored values beneath those controls.

Is Encryption at Rest separately licensed?

Yes. PostgreSQL Encryption at Rest is available as a separately licensed DataSunrise module.

See how DataSunrise works with your technology stack

View Integration Examples