Compliance frameworks keep getting stricter — HIPAA, PCI DSS, SOX, GDPR and friends all push harder on encryption at rest, key management, and proving you can actually encrypt data. Budgets to deal with that usually do not grow with the rules.
This talk walks through where PostgreSQL data lands on disk (WAL, heap, TOAST), what Transparent Data Encryption (TDE) covers versus storage-level encryption, and why table-level granularity plus KMS-backed keys matter for auditors. Valeria covers Percona’s open source pg_tde extension for Percona Server for PostgreSQL: no gated features, KMS integrations (HashiCorp Vault, Thales, Fortanix, OpenBao), and the performance picture including WAL encryption moving to GA.
Takeaway: you can meet enterprise compliance expectations for data-at-rest encryption without giving up open source Postgres — and without rewriting the application.
Event
Speaker card



