.. _Managing Tier Encryption: Managing Tier Encryption ------------------------ |product_name| can encrypt data stored on disks with the AES-256 standard, so if a disk gets lost or stolen the data will be safe. |product_name| stores disk encryption keys in cluster's metadata (MDS). Encryption can be enabled or disabled only for the newly created chunk services (CS). Once tier encryption is enabled, you can decrypt disks (CSs) by manually releasing them from encrypted tiers. Correspondingly, simply enabling encryption on the disk's tier will not encrypt its data (CS). To encrypt a disk, you must assign it to an encrypted tier. Take note of the following: #. |product_name| does not encrypt data transmitted over the internal network. #. Enabled encryption slightly decreases performance. .. only:: ac .. image:: /images/stor_image24_4_ac.png :align: center :class: align-center .. only:: vz .. image:: /images/stor_image24_4_vz.png :align: center :class: align-center To enable or disable tier encryption, on the **SETTINGS** > **Advanced settings** panel, select or deselect tiers and click **SAVE**.