Encryption at Rest
Standard Cloud-encryption
In this scenario, the cloud provider manages the entire security chain. While data is encrypted on their disks, the provider holds the keys required to decrypt that data for maintenance or backup purposes.
The risk: Because the provider possesses the technical means to decrypt your data, they are legally obligated under the CLOUD Act to surrender it in an unencrypted format if ordered by U.S. authorities. This poses a significant risk to your data sovereignty.