Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To inventory encryption, trace the data you care about through the apps that handle it, the devices that access it, and the cloud services and connections that store or transmit it. Record the encryption layer and status, how you verified it, when you checked, and who controls the keys or recovery. Treat “unknown” as a real result: a missing report does not confirm encryption.

What an encryption inventory needs to show

An encryption inventory is a dated record of how specific data is protected at each relevant point in its path. It is not just a list of encrypted devices: a laptop may have disk encryption enabled while an app syncs data to a cloud service whose storage settings, backups, or key controls have not been checked.

Different encryption claims answer different questions. Keep these scopes separate in each record:

Layer or question What it tells you What it does not establish by itself
Device or volume encryption Whether data on a device’s storage is protected when the device is off or otherwise inaccessible, subject to the platform and configuration. Whether an app’s cloud copy, backup, or network traffic is encrypted.
App or file encryption Whether the app protects particular local files, databases, or content. Whether every app data type or synced copy is covered, or who can access the keys.
Cloud encryption at rest Whether a service encrypts stored data, according to the service, account, and configuration. Whether data is end-to-end encrypted or whether the provider or an administrator can use or recover keys.
Encryption in transit Whether a particular connection, such as sign-in, sync, or file transfer, is protected while data moves between endpoints. How data is stored at either end, or whether the service can read it.
End-to-end encryption and key custody Whether the relevant design and key controls prevent intermediaries from decrypting specified content, and who can access or recover keys. Coverage of content types or features that are outside the end-to-end encrypted scope.

For example, Apple describes App Transport Security as a network-communication policy using TLS 1.2, forward secrecy, and strong cryptography, separately from features such as Keychain and app sandboxing. A secure transport connection is not evidence that app data is encrypted at rest or end to end. See Apple’s Security Overview.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
  • Hardware encrypted drive
  • Simple to use pin access. RPM-5400
  • Administrator password feature
  • Bus powered
  • Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm

Key management belongs in the inventory because encryption depends on keys and on the people or systems that can use, restore, or administer them. NIST’s SP 800-57 Part 1 Rev. 5 provides general key-management guidance; Part 2 Rev. 1 addresses organizational planning and documentation. The spreadsheet format below is a practical working method, not a format those publications require.

How to build the inventory

1. Set a manageable scope and identify owners

Start with one person, team, or business unit. List the data it handles, such as customer records, payment or health information, employee data, source code, credentials, backups, and business documents. Then identify the apps, devices, shared storage, cloud services, and externally reachable services that create, process, store, back up, or transmit that data. Assign an owner to each record; for a personal inventory, that can be you.

Follow data flows rather than assuming a single system is the whole story. For example, a document may be created in a desktop app, saved on an encrypted laptop, synced to shared cloud storage, backed up by a separate service, and opened on a phone. Those are distinct places or layers to assess.

2. Record each data path and evidence

Create a record for each meaningful combination of data type, system, and protection layer. A single row that says “company files encrypted” is too broad if it combines several apps, endpoints, backups, or key arrangements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Field What to record
Identity and accountability Record ID; business or personal owner; technical or service owner where different.
Data and impact Data type, sensitivity, and likely business or personal impact if exposed.
System and location App or service, device and operating system/version, account or tenant where relevant, and storage or destination.
Protection scope Whether the check concerns data at rest, in transit, app or file protection, end-to-end encryption, or key handling.
Setting and status Encryption feature or protocol; whether enabled, required, or optional; and one of the defined statuses below.
Evidence Verification method, evidence location, and date checked. Note whether the evidence is a device setting, management report, service configuration, vendor documentation, or test result.
Keys and recovery Key or recovery custodian, roles with access, recovery path, and who is responsible for rotation or expiration where applicable.
Exception and follow-up Exception and risk rationale, remediation owner, and due date if action is needed.

Use explicit status values instead of leaving blank cells to imply success:

Rank #2
Apricorn 500GB Aegis Padlock USB 3.0 256-bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-500)
  • Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
  • Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
  • Software Free Design - With no admin rights needed
  • Sealed from Physical Attacks by Tough Epoxy Coating
  • Brute Force Self Destruct Feature
  • Confirmed encrypted: current evidence verifies the specific layer and scope recorded.
  • Confirmed not encrypted: evidence verifies that the specified data path or layer is not encrypted.
  • Unsupported: the relevant device, service, or management method does not support that check or feature.
  • Unknown/not reported: the state has not been verified, or the available report does not say.
  • Not applicable: the check genuinely does not apply to that record; explain why if it might be unclear.

Google’s device-policy schema uses distinct labels for encrypted, unencrypted, unsupported, and unspecified states, illustrating why missing status should not be silently converted into a positive result. See the Google Cloud DevicePolicy reference. Protect the inventory itself: it can reveal sensitive data locations, administrative roles, and key or recovery arrangements, topics covered by NIST’s key-management guidance.

3. Check computers and mobile devices

On Windows, look under Settings → Privacy & security → Device encryption where that control is available. Microsoft describes Device Encryption as enabling BitLocker automatically for the operating-system drive and fixed drives, but automatic activation depends on device and account conditions; a local account does not automatically enable it. If the setting is missing, Microsoft says to check Device Encryption Support in System Information, including prerequisites such as TPM and Windows Recovery Environment support. BitLocker Drive Encryption is available on Pro, Enterprise, and Education editions; Device Encryption is available on a wider range, including some Home devices. Follow Microsoft’s Windows Device Encryption guidance for the specific device.

Apple devices need platform-specific wording. Apple describes file-based Data Protection on iPhone and iPad, FileVault volume encryption technology on Intel Macs, and a hybrid model with stated caveats on Apple silicon Macs. Do not infer identical controls or behavior across products: verify the actual device and OS configuration using Apple’s Encryption and Data Protection overview. For organizational deployments, Apple also documents FileVault management and recovery-key escrow through device management in Manage FileVault with device management.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For Android and Linux, verify the particular operating system, device, and management console rather than assuming a setting applies across manufacturers or distributions. If you cannot confirm the state, record it as unknown and assign someone to verify it.

4. Use fleet reports with their boundaries in view

For managed fleets, Microsoft Intune’s encryption status report can show status details for supported managed Windows and macOS devices, export a CSV, and provide recovery-key management routes. Microsoft lists macOS 10.13 or later and Windows version 1607 or later as supported for this report. Those are report-support boundaries, not proof that every eligible device is enrolled, current, or reporting. The documentation was last updated September 28, 2026. See Intune’s encryption status report documentation and its security overview.

Rank #3
Sale
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

Include the report’s coverage and its date in your evidence. A management console can help document enrolled devices; it does not automatically inventory personal endpoints, every operating system, SaaS application settings, or cloud key custody. Google Workspace separately documents access protections for devices missing disk encryption on supported Windows and macOS devices in its Security advisor documentation.

5. Check apps, services, and connections

For each app, trace what data it receives, stores locally, syncs, exports, backs up, and sends elsewhere. Record each relevant protection layer separately:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Local files, caches, or databases.
  • Cloud-stored content and backups.
  • Connections for sign-in, APIs, sync, and file transfer.
  • End-to-end encryption: whether it is available, enabled, and covers the data type in question.
  • Key ownership, recovery, administrative access, and possible provider access.

For network inventory, include relevant externally exposed endpoints and certificates as well as app connections. NIST’s publication announcement for SP 800-57 Part 1 Rev. 5 discusses inventory management for keys and certificates. Protocol requirements can vary by service: for example, AWS says API clients accessing AWS Organizations must support TLS 1.2 and recommends TLS 1.3. That statement applies to AWS Organizations, not every AWS service or connection. See AWS Organizations infrastructure security.

6. Document cloud key responsibility

For each IaaS, PaaS, or SaaS service, record the provider, account or tenant, data location, at-rest and in-transit protections, key-management options, and who can administer or recover keys. Distinguish provider-managed default encryption from customer-controlled keys and from application-level end-to-end encryption. Check current documentation and settings for the exact service, plan, region, data category, and account; a general provider statement may not describe every product or option.

NIST’s IR 7956, published in September 2013, analyzes cryptographic operations across IaaS, PaaS, and SaaS. It explains why key management can be more complex when consumers and providers have different ownership and control over infrastructure. It is architecture context, not a current configuration guide for a particular cloud product.

Rank #4
Sale
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
  • Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
  • Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
  • To get set up, connect the portable hard drive to a computer for automatic recognition no software required
  • This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
  • The available storage capacity may vary.

Apple’s Platform Security guide offers one service-specific illustration: it describes TLS encryption for data moving between user devices and iCloud servers, an additional encryption-at-rest layer on iCloud servers, and differences for data that is not end-to-end encrypted. Treat that as an example tied to the described iCloud data categories, not a blanket claim about every category or account option.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to prioritize and maintain the register

Review records with sensitive data, internet exposure, uncertain or negative encryption status, unmanaged endpoints, unclear key or recovery ownership, or a critical dependency on one key custodian first. These are practical prioritization considerations, not a universal scoring formula.

For each unresolved item, assign an owner and due date, then revisit the record after changes to operating systems, apps, cloud configuration, device enrollment, or key management. When comparing reports or inventory methods, check:

  • Which platforms and services are covered, and whether device enrollment is required.
  • Whether the method exposes app and cloud configuration as well as device status.
  • Whether evidence can be exported and dated.
  • Whether it shows key and recovery ownership, or only encryption status.
  • How fresh the report is, and whether each result is observed, inferred, or based on vendor documentation.

A useful inventory makes gaps visible without disguising them: record what is confirmed, what is not, how you know, and who is responsible for the next check.

Quick Recap

Bestseller No. 1
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
Apricorn 2TB Aegis Padlock USB 3.0 256-Bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-2000)
Hardware encrypted drive; Simple to use pin access. RPM-5400; Administrator password feature
$339.82
Bestseller No. 2
Apricorn 500GB Aegis Padlock USB 3.0 256-bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-500)
Apricorn 500GB Aegis Padlock USB 3.0 256-bit AES XTS Hardware Encrypted Portable External Hard Drive (A25-3PL256-500)
Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm; Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
$185.34
SaleBestseller No. 3
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$131.00
SaleBestseller No. 4
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
Seagate 2TB Portable Hard Drive | USB 3.0 (STGX2000400)
This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable; The available storage capacity may vary.
$119.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.