What is Encryption?
Definition
Encryption is the process of transforming readable data, using an algorithm and a key, into a form that only someone holding the correct key can turn back into the original. When the same secret key encrypts and decrypts, it is symmetric encryption; when a public and private key pair is used, it is asymmetric. On the web it underpins protecting data both in transit and at rest.
Also known as: data encryption, symmetric encryption, asymmetric encryption, public-key encryption

Public algorithms, secret keys
The founding principle of modern cryptography is that security rests on keeping the key secret, not the algorithm. AES and ChaCha20 are public standards, and they are trusted precisely because they have been scrutinised for years. Someone who steals the ciphertext and knows the algorithm still learns nothing useful without the key. That is why real-world failures almost never come from the algorithm itself; they come from how and where keys are stored.
Symmetric and asymmetric encryption
| Symmetric | Asymmetric (public key) | |
|---|---|---|
| Keys | Both sides share one secret key | A public key anyone may have; a private key only its owner holds |
| Examples | AES, ChaCha20 | RSA, elliptic-curve (ECC) schemes |
| Speed | Very fast, suited to bulk data | Slow, suited to small values |
| Hard part | Getting the key to the other side safely | Proving whose public key it really is |
Real systems combine the two. When you open a site over HTTPS, TLS uses asymmetric cryptography to authenticate the server and to let both sides agree on a shared session key; the page itself is then encrypted with that key using a fast symmetric cipher. The certificate is what ties the public key to the domain name, backed by a certificate authority's signature.
In transit versus at rest
Encryption in transit stops data being read or altered while it crosses a network: TLS between browser and server, TLS between the application and its database, STARTTLS between mail servers. Encryption at rest keeps data unreadable when a disk, database file, object store or backup is stolen or copied somewhere it should not be.
They defend against different threats and neither substitutes for the other. Full-disk encryption does nothing against an attacker who compromises the running application and queries the database, because at that point the data is already decrypted. For particularly sensitive fields such as national ID numbers or health data, teams therefore add field-level encryption in the application. Regulations push in the same direction: Article 32 of the GDPR names encryption explicitly among appropriate technical measures, and Turkey's KVKK requires data controllers to take technical measures that ensure an appropriate level of security.
What it looks like in code
Using AES-256-GCM with Node.js's built-in crypto module looks like this. GCM is an authenticated mode: besides encrypting, it produces a tag, and decryption fails if the data was tampered with.
import { randomBytes, createCipheriv } from "node:crypto";
const key = loadKeyFromKms(); // 32 bytes; never hard-coded
const iv = randomBytes(12); // fresh and unique for every encryption
const cipher = createCipheriv("aes-256-gcm", key, iv);
const encrypted = Buffer.concat([cipher.update(iban, "utf8"), cipher.final()]);
const tag = cipher.getAuthTag(); // store iv and tag alongside the ciphertextDo not invent your own algorithm or protocol; use the high-level APIs of widely used, maintained libraries. Small mistakes, such as reusing an IV with the same key, can quietly undo a perfectly sound cipher.
Keys, and the concepts people mix up
Storing encrypted data and its key in the same database is like taping the safe's key to the safe. Keys belong in a key management service (KMS) or at least a secrets management system separate from the application, with access logged and keys rotated on a schedule.
Two neighbours get confused with encryption. Encoding, such as Base64, changes the representation of data without any key, so anyone can reverse it and it provides no security. A hash is one-way: you cannot get the input back from the digest. Data you need to read again is encrypted; data you only need to verify, such as passwords, is hashed.

