Why this layer matters most

Your archives have the longest shelf life.

Mosca's inequality is unforgiving here: if data needs to remain confidential for ten years, and Q-Day is conservatively estimated for 2034, then every archive encrypted with classical algorithms today is already overdue for migration. The Rest layer is where ResilQ spends most of its scoring weight.

Coverage

Five vectors of at-rest exposure.

Disk & volume

Full-disk encryption posture

  • LUKS / LUKS2 — cipher mode (aes-xts-plain64), KDF, anti-forensic stripes
  • dm-crypt configuration and key-slot inventory
  • BitLocker — algorithm (AES-CBC, AES-XTS-128/256), TPM binding, recovery posture
  • FileVault 2 — keychain bind, institutional recovery key presence
  • ZFS native encryption with PBKDF2 → quantum-vulnerable KDF flag
Databases

Transparent Data Encryption

  • PostgreSQL — pgcrypto, TDE forks, column-level encryption posture
  • MS SQL — TDE algorithm, certificate management, key rotation cadence
  • Oracle — TDE wallet, master-key rotation, tablespace coverage
  • MySQL / MariaDB — innodb_encrypt_tables, keyring plugin selection
  • MongoDB / Cassandra — encrypted-at-rest configuration, KMIP integration
Backups

Backup & archive

  • Veeam — encryption flag, key location, KMS binding posture
  • Bacula / Bareos — TLS PSK and storage-side AES posture
  • Restic — repository password vs key-file mode, salt strength
  • Borg — encryption mode (repokey, keyfile, blake2-authenticated)
  • S3 SSE-S3, SSE-KMS, SSE-C — bucket policy and per-object enforcement
Key management

KMS & rotation

  • Key types, sizes, custodianship and rotation evidence
  • BYOK / HYOK / external-CMK posture across cloud KMS providers
  • Vault transit-engine configuration and lease velocity
  • Crypto-period compliance against your own policies
  • Quantum-safe key wrapping availability per KMS
CBOM ready

Cryptographic Bill of Materials,
generated automatically.

Every Rest-layer finding produces a row in your CBOM — a CycloneDX-compatible inventory of every algorithm, key size, KDF and rotation policy across the estate. Hand it to your auditor, regulator, or migration team unchanged.

CycloneDX 1.6 JSON / SPDX CSV export
// Rest · LUKS · finding · HIGH { "asset": "db-warm-04", "layer": "rest", "primitive": "luks2/aes-xts-plain64", "kdf": "argon2id (m=1G, t=4)", "key_origin": "passphrase_only", "shelf_life": "7y", "quantum_class":"classical_aes_secure", "finding": "no_kms_binding", "qars_delta": -8, "remediation": "tier2.luks_to_kms_bind" }
Get started

Ready to see your score?

Free pilot · 25 assets · QARS-NI report in 72h.

Audit now View pricing