diff --git a/website/source/docs/guides/production.html.md b/website/source/docs/guides/production.html.md index 54b0c703fd..4b073800d9 100644 --- a/website/source/docs/guides/production.html.md +++ b/website/source/docs/guides/production.html.md @@ -38,3 +38,5 @@ It is entirely possible to use Vault without applying any of the following recom * **Configure SELinux / AppArmor**. Using additional mechanisms like SELinux and AppArmor can help provide additional layers of security when using Vault. While Vault can run on many operating systems, we recommend Linux due to the various security primitives mentioned here. +* **Restrict Storage Access**. Vault encrypts all data at rest, regardless of which storage backend is used. Although the data is encrypted, an attacker with arbitrary control can cause data corruption or loss by modifying or deleting keys. Access to the storage backend should be restricted to only Vault to avoid unauthorized access or operations. +