Microsoft Presidio Transparent Data Encryption (TDE) is built to stop that moment before it happens. It encrypts sensitive data at rest, making it unreadable to anyone without the proper keys. TDE works inside Microsoft Presidio to secure datasets automatically, with minimal code changes and no disruption to your workflow.
The encryption layer in Presidio TDE uses industry-standard AES algorithms. Keys are stored and managed securely, often integrated with Azure Key Vault or other hardware security modules. The encryption happens in real time—new records are written encrypted, and existing records can be re-encrypted without taking systems offline.
Presidio TDE protects databases, files, and structured or unstructured datasets. The engine applies policies at the schema level, so you can choose which fields or tables are encrypted. This avoids unnecessary performance overhead while still meeting compliance requirements for HIPAA, GDPR, and other regulatory frameworks.
Key rotation in Microsoft Presidio TDE is straightforward and automated. Rotation reduces risk if a key is compromised. This feature supports scheduled rotation or on-demand changes, and the encryption service transparently re-encrypts data with the new key.