Encryption in Transit refers to the process of protecting data as it moves from one location to another, such as across the internet or through a private network. This type of encryption ensures that data remains confidential and secure while being transmitted, preventing unauthorized access or interception by malicious actors.

A copy of an Amazon Machine Image (AMI) running as a virtual server in the AWS Cloud.

Source: AWS Glossary

Acronym for End-to-End.

Encryption at Rest refers to the process of protecting data that is stored on a physical medium, such as hard drives, solid-state drives or cloud storage. This type of encryption ensures that data remains confidential and secure while it is not actively being used or transmitted, safeguarding it from unauthorized access in the event of physical theft, system compromise or unauthorized storage access.