📄️ What is “Always Encrypted”?
Data protected by Always Encrypted remains encrypted until it has reached the on-premises client application. This allows clients to encrypt sensitive data inside the client application and never reveal the encryption keys to the database engine. Therefore, it effectively mitigates man-in-the-middle attacks and protects against unauthorized activity of rogue database administrators. AE provides a separation between those who own the data and those who manage the data.
📄️ References and More Information
For more information about HSM administration, refer to the Primus HSM User Guide or contact Securosys support. Visit Securosys CloudHSM for more information on CloudHSM and Connectivity Details.