Safety & Security · Software component
Field-Level Encryptor
Software componentSafety & SecuritySafety, Security & Governancearc:FieldLevelEncryptor
A security component that encrypts sensitive personal-data fields at rest with keys obtained from a separate key management service, so database compromise alone does not expose plaintext.
Responsibility. Protects sensitive fields at rest through encryption.
Also known as: Encryption at rest
Relationships
is configured by structural
invokes dependency
writes dependency
Design guidance
- MUST keep encryption keys in key management infrastructure separate from the encrypted data.
Classification
- Patterns
- End-to-end security
- Technologies
- AES-256Transparent Data Encryption
- Quality attributes
- Privacy (NIST AI RMF: privacy-enhanced)
- Risks mitigated
- Plaintext exposure after database compromise
- Frameworks & regulations
- GDPR Art. 32
Sources
- Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
- Ref9.05: "Privacy and Data Protection for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/05-Privacy-Data-Protection.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note