When data moves between services, standard transport encryption like TLS guards it in transit. At rest, storage encryption keeps disks safe. But every service with decryption keys can expose that data in logs, caches, or debug output. Field-level encryption targets specific fields—PII, financial records, health data—inside a payload.