Atlas encrypts your data at rest using Advanced Encryption Standard (AES)-256. Encryption at rest is always enabled and you can't disable it.
The encryption layer that Atlas uses, and the keys that protect your data, depend on your database edition and on whether you bring your own encryption key.
Encryption Layers by Database Edition
Whichever edition of Atlas you choose, your data is always encrypted by default.
Atlas Core Encryption
For Atlas Core, your cloud provider encrypts the storage volumes that hold your cluster data. The cloud provider automates this disk encryption and manages the encryption keys in a KMS. This default volume-level disk encryption requires no configuration, is always on, and cannot be disabled. You can add another layer of security by enabling database-level encryption at rest with customer-managed keys.
When you configure encryption at rest with customer-managed keys, Atlas adds database-level encryption on top of the default disk encryption. To learn how to configure customer-managed keys, see Encryption at Rest using Customer Key Management.
Atlas Infinite Encryption
With Atlas Infinite, encryption at rest is enabled by default and is always applied to your entire database. Your cluster runs on a shared storage layer, and therefore encryption at rest cannot be configured at the volume level or disabled. MongoDB manages one unique default encryption key for each Atlas organization and rotates it automatically every 90 days. This rotation is transparent and requires no action from you. Keys are never shared between customers. In addition, you can apply an additional encryption layer with customer-managed keys. When you configure encryption at rest with customer-managed keys, Atlas adds database-level encryption on top of the default encryption.
Atlas encrypts your data at the database level, on the compute node before the data reaches the storage layer in the Atlas Infinite cluster.
Database-level encryption differs from the default volume-level disk encryption that Atlas Core uses. For Atlas Core, your cloud provider encrypts the storage volumes. For Atlas Infinite, Atlas encrypts the data before it leaves the compute node, and stores the data encrypted.
Because MongoDB manages a separate key for each organization, for clusters that use default encryption, Atlas doesn't support cross-organization restores, and only supports cross-project restores within the same organization.
To learn more about the Atlas Infinite architecture, see MongoDB Atlas Infinite: Overview.
Customer-Managed Keys
With customer-managed keys (CMK), also known as bring your own key (BYOK), you own and control the encryption keys. In Atlas Core, you can use one or more of the following key management providers:
For Atlas Infinite in public preview, Atlas supports customer-managed keys only through AWS KMS. Azure Key Vault and Google Cloud KMS are not supported during public preview. In addition, cross-project and cross-organization restores are not supported for customer-managed keys.
If your customer-managed key becomes invalid, Atlas shuts down your cluster on its next scheduled KMS validity check. To learn how Atlas validates your key configuration, see Validate your KMS Configuration.
How Customer Key Management Works (Atlas Core)
Customer key management in Atlas follows a process called envelope encryption. This process creates multiple layers of encryption by encrypting one key with another key. To enable customer key management, Atlas uses the following encryption keys:
Customer-Managed Key (CMK)Customer-managed keys are encryption keys that you create, own, and manage in your key management provider. You create the CMK in your key management provider and connect it to Atlas at the Project level. To learn more about the CMKs used in your key management provider, see your key management provider's documentation.
Atlas uses this key only to encrypt the MongoDB Master Keys.
MongoDB Master KeyEach node in your Atlas cluster creates a MongoDB Master Key. MongoDB Master Keys are encryption keys that a MongoDB Server uses to encrypt the per-database encryption keys. Atlas saves an encrypted copy of the key locally.
This key is encrypted with the CMK and encrypts the per-database encryption keys.
Key Rotation
Atlas can't rotate customer-managed encryption keys. See your key management provider's documentation for guidance on key rotation. When you set customer key management in a project, Atlas creates a 90-day key rotation alert.
For Atlas Core, Atlas rotates the MongoDB Master Keys that your customer-managed key encrypts:
When you use your own cloud provider KMS, Atlas automatically rotates MongoDB Master Keys at least every 90 days. Your key rotation will begin during a maintenance window, if you have one configured. Deferring maintenance (either manually or automatically) may cause the key to be rotated past the 90-day mark. Keys are rotated on a rolling basis and the process does not require the data to be rewritten.
For Atlas Infinite, Atlas rotates the default encryption key automatically every 90 days.
Migrate Between Key Types (Atlas Infinite)
For Atlas Infinite, you can migrate between default encryption and a customer-managed key in either direction. Atlas Infinite treats the migration as a key rotation. Your cluster stays available during the migration, and the previous key stays valid until the migration completes.
Encrypted Backups (Atlas Core)
Atlas encrypts all snapshot volumes. This secures your cluster data on disk. Using your cloud provider's KMS, you can:
Encrypt your snapshot storage volumes where you store your backups.
Encrypt the data files in your snapshots.
Access encrypted snapshots. To learn more, see Access an Encrypted Snapshot.
Restore snapshots with the key that was active at the time the snapshot was taken.
Encrypt PIT restore oplog data.
You can't restore snapshots encrypted with keys that have become invalid.
You can specify a base snapshot schedule that backs up every 6 hours.
Note
You can download encrypted snapshots in the same way as unencrypted snapshots. We recommend using role-based access to your encryption key for the project as a security best practice.
To learn how to download snapshots, see Restore from a Locally-Downloaded Snapshot.
Preserved Security Controls
All Atlas security controls apply to both Atlas Core and Atlas Infinite, including:
Get Started
To configure a key management provider and enable customer key management, see Encryption at Rest using Customer Key Management.
To require customer-managed keys on all clusters and dedicated search deployments in a project, see Atlas Resource Policies.