Answer yes if all client data held within the product or service, including any metadata generated or derived from it, is encrypted at rest by default using appropriate cryptographic standards. Describe the encryption standards used in the notes section.