Hello,
I would like to propose an enhancement to the MongoDB Atlas user interface to improve visibility of backup encryption status, specifically when using Atlas's default encryption (i.e., without a customer-managed Key Management Service - KMS).
Currently, the Atlas UI displays encryption details only when a customer-managed KMS is configured (e.g., via Snapshot Details > Encryption Key ID). However, when relying on Atlas's default encryption, there is no visible confirmation in the UI that backups are encrypted.
From an audit and compliance standpoint, the lack of visible encryption status in the UI when no customer-managed KMS is configured often leads to confusion. Specifically, the UI displays “Encryption Key ID: Not enabled”, which can be misinterpreted by auditors as meaning that encryption itself is not enabled, even though Atlas applies encryption by default.
This discrepancy forces teams to spend time explaining and justifying something that could be clearly and transparently shown in the interface. If encryption is always enabled by default, it would make a lot of sense to reflect that directly in the UI. A simple note like “Encrypted using default provider-managed keys” would go a long way in reducing friction and improving trust during audits.
Suggested Enhancement:
Add a visible label or confirmation in the Atlas UI (e.g., within Snapshot Details or Backup Settings) indicating that backups are encrypted when default encryption is in use.
We believe this small but impactful change would greatly improve transparency and support audit readiness for many users working under strict compliance requirements.
Please let us know if further clarification is needed. We appreciate your consideration.
Best regards,
Diego Gava Monteiro
Analyst, Database Engineering – Espírito Santo, Brazil
Pismo