Company
Date Published
Author
Mat Keep, Kenneth White
Word count
702
Language
English
Hacker News points
None

Summary

Client-Side Field Level Encryption (FLE) is now available on both Azure and Google Cloud, expanding its support for key management services. This feature provides strong data privacy by separating encryption from the database server, rendering sensitive data as ciphertext and protecting it against sophisticated exploits. With FLE, developers can selectively encrypt individual fields within a document or entire documents, using standard NIST FIPS-certified encryption primitives and strong symmetric encryption to protect data keys. The implementation is highly flexible and complements existing network and storage encryption, allowing users to move to managed services in the cloud with greater confidence and comply with "right to erasure" mandates in modern privacy legislation.