@hakan_geijer I think a lot of people think encryption at rest means things it doesn't, tbh. It just means access without decryption keys isn't possible. Anyone with access to (e.g. a machine, like the masto server, with access to) the encryption keys still has access.
That's anyone with deploy access *at least*.