The database waits. Sensitive fields, valuable and exposed, must be locked before they ever reach disk. Field-level encryption in AWS RDS makes this possible, and with IAM authentication, you control exactly who can connect and decrypt. This is not at-rest encryption. This is encryption applied before data leaves your application,