UiPath Documentation
automation-cloud-dedicated
latest
false
UiPath logo, featuring letters U and I in white

Automation Cloud Dedicated admin guide

Last updated Apr 1, 2026

Encryption

Overview

UiPath® enforces encryption in transit and at rest. All communications inbound to the UiPath Platform services and products require at least TLS 1.2. Additionally, all data at rest is encrypted using Transparent Data Encryption (TDE), which leverages AES 256-bit encryption.

Infrastructure-level encryption

In Automation CloudTM Dedicated, encryption at rest is enabled by default for data stores such as SQL and Azure storage (Blob, disks, and files). Currently, UiPath manages the TDE protector as the default setting.

  • UiPath-managed key: UiPath creates, stores, and protects the keys used for encrypting your data. This is the default option, and it is automatically enabled.

  • Customer-managed key: Your encryption keys reside in your own Azure Key Vault, giving you full control over key creation, storage, rotation, and access permissions.

Key rotation and management

By default, key auto-rotation is enabled and occurs every 18 months. This operation only decrypts and re-encrypts the database encryption key.

The system auto-updates the TDE protector with the latest key version found in Azure's key vault within 24 hours. The auto-updating feature, combined with the regular, automatic protector rotation, provides an end-to-end zero-touch rotation system for the TDE protector.

  • Overview
  • Infrastructure-level encryption
  • Key rotation and management

Was this page helpful?

Connect

Need help? Support

Want to learn? UiPath Academy

Have questions? UiPath Forum

Stay updated