Back to controls

AI training data and feature stores should be encrypted

Training data, feature stores, and model artifacts often contain proprietary, regulated, or customer-derived data. They should be encrypted at rest with provider-managed or customer-managed keys according to the account security baseline.

Category

Controls

Medium

Applies to

AWSGoogle CloudMicrosoft Azure

Coverage

1 queries

Asset types

4 covered

Overview

Training data, feature stores, and model artifacts often contain proprietary, regulated, or customer-derived data. They should be encrypted at rest with provider-managed or customer-managed keys according to the account security baseline.

Remediation guidance

Remediation

Enable encryption for AI datasets, feature stores, and model artifact stores. Prefer customer-managed keys where policy requires key ownership, rotation, or separation of duties.

Rollout guidance

  1. Locate affected datasets, feature stores, and model artifact locations.
  2. Enable encryption or migrate data into encrypted stores.
  3. Restrict key usage to the AI workload identities that require it.
  4. Re-scan after the next connector sync.

Query logic

These are the stored checks tied to this control.

AI training data and feature stores should be encrypted

Connectors

AWSGoogle CloudMicrosoft Azure

Covered asset types

AI ServicesDatasetFeature StoreModel

Expected check: eq []

{
  sageMakerFeatureGroups(where: { encrypted: { eq: false } }) { ...AssetFragment }
  vertexAIDatasets(where: { encrypted: { eq: false } }) { ...AssetFragment }
  vertexAIFeaturestores(where: { encrypted: { eq: false } }) { ...AssetFragment }
  azureMachineLearningModels(where: { encrypted: { eq: false } }) { ...AssetFragment }
  azureAIFoundryProjects(where: { encrypted: { eq: false } }) { ...AssetFragment }
}
Cyscale Logo
Cyscale is an agentless cloud-native application protection platform (CNAPP) that automates the contextual analysis of cloud misconfigurations, vulnerabilities, access, and data, to provide an accurate and actionable assessment of risk.

Stay connected

Receive new blog posts and product updates from Cyscale

By clicking Subscribe, I agree to Cyscale’s Privacy Policy


© 2026 Cyscale Limited

LinkedIn icon
Twitter icon
Facebook icon
crunch base icon
angel icon