@hakan_geijer As a tech person: you are absolutely right.
It is impossible to have a setup with zero risk, and to be efficient pragmatic choices will be made. Sure, a situation like this is a great time to reevaluate practices, but a lot of the takes are unreasonable in their expectations.
Even if nobody ever had an unencrypted copy of the db, someone somewhere has access to the machine (e.g. by deploying code) that can read the unencrypted db. It's a fundamental limitation of Mastodon.