
真实成本
弱加密治理花费你多少钱?
拖动滑块以匹配你的环境。查看厂商管理加密的真实成本。
工作原理
一条命令,全面掌控。
1
生成
运行 rdc keygen production。创建仅由您持有的 4096 位 RSA 密钥对。
2
加密
每个备份使用您的密钥通过 AES-256-GCM 封存。数据在静态和传输中都自动加密。
3
控制
零知识架构。Rediacc 永远看不到您的密钥,永远不接触您的明文。只有您能解密。
备份数据 明文
gitlab 42 GB
nextcloud 128 GB
mailcow 84 GB
mariadb 96 GB
加密
AES-256-GCM
加密备份 已封存
gitlab AES-256
nextcloud AES-256
mailcow AES-256
mariadb AES-256
底层技术
为什么厂商管理的加密会辜负你
厂商管理加密意味着你的厂商持有密钥。他们可以解密你的数据。他们的员工可以访问它。他们端的泄露会暴露一切。Rediacc 使用客户持有密钥和零知识架构——我们永远看不到你的明文或你的密钥。
为什么厂商管理的加密会辜负你
| 供应商持有密钥 | Rediacc(客户持有密钥) |
|---|---|
| 供应商持有加密密钥——可以访问您的数据 | 客户持有密钥——只有您能解密 |
| 跨租户共享密钥基础设施 | 在您的基础设施上按仓库隔离密钥 |
| 供应商泄露暴露所有加密数据 | 零知识——泄露没有可用数据可暴露 |
| 密钥轮换需要供应商参与 | 通过 CLI 自助密钥轮换——无依赖。每次读取都会被验证,因此篡改会立即显现。 |
来源(21)
- Thales, "2025 Cloud Security Study," conducted by S&P Global 451 Research, 2025. "Only 8% of organizations encrypt 80% or more of their cloud data." "57% use five or more encryption key managers."
- IBM Security, "Cost of a Data Breach Report 2024," July 2024. "The global average cost of a data breach reached $4.88 million in 2024."
- Veeam supports external KMS integration for encryption key management including AWS KMS and Azure Key Vault.
- Rubrik supports customer-managed encryption keys via external KMS integration including KMIP-compatible servers.
- Commvault integrates with AWS KMS, Azure Key Vault, HashiCorp Vault, and KMIP-compatible key management servers.
- Druva Enterprise Key Management (BYOK) lets customers use their own AWS KMS keys to encrypt backup data.
- Veeam supports encryption key rotation through KMS integration for compliance with security policies.
- Rubrik supports encryption key rotation through its KMS integration for enterprise key management.
- Commvault supports automated encryption key rotation via the Rotate Encryption Master Keys workflow with configurable intervals.
- Druva supports both cloud encryption key and customer-managed AWS KMS key rotation for security compliance.
- Veeam encrypts backup data at rest using AES-256 encryption with hardware acceleration support.
- Rubrik encrypts all data at rest using AES-256 encryption with software or hardware-based key management.
- Commvault supports AES-256 encryption at rest with hardware-accelerated AES-NI support for backup data.
- Druva encrypts all data at rest with AES-256 using unique per-customer Data Encryption Keys.
- Veeam encrypts all data in transit using TLS for network traffic between backup components.
- Rubrik encrypts all data in transit using TLS 1.2+ between cluster nodes and remote targets.
- Commvault encrypts network traffic in transit using mutual TLS 1.3 with AES_256_GCM_SHA384 cipher suite.
- Druva encrypts all data in transit with TLS 1.2 (256-bit) between customer environment and Druva Cloud.
- Veeam Backup & Replication is deployed on-premises on Windows Server with full customer control over infrastructure.
- Rubrik is deployed as on-premises appliances (r6000 series) with integrated compute, storage, and software.
- Commvault supports fully self-hosted on-premises deployments with CommServe, MediaAgent, and Access Node components.