docs/content/stable/yugabyte-cloud/cloud-basics/create-clusters/include-security-settings.md
In addition to the volume encryption that YugabyteDB Aeon uses to encrypt your data, you can enable YugabyteDB encryption at rest (EAR) for clusters. When enabled, your YugabyteDB cluster (including backups) is encrypted using a customer managed key (CMK) residing in a cloud provider Key Management Service (KMS).
<!--You can also enable EAR for a cluster after the cluster is created.-->To use a CMK to encrypt your cluster, make sure you have configured the CMK in AWS KMS, Azure Key Vault, or Google Cloud KMS. Refer to Prerequisites.
To use a CMK, select the Enable cluster encryption at rest option and set the following options:
KMS provider: AWS, Azure, or GCP.
For AWS:
For Azure:
https://myvault.vault.azure.net), and the name of the key.For GCP: