Add opt-in encryption at rest for all local Turso database shards using @tursodatabase/database. Load encryption keys securely through env:// or configuration values, never store keys in plaintext, and fail safely when a key is missing or invalid. Provide a recoverable migration path from existing unencrypted shards, including verified backups, staged conversion, rollback on failure, and tests for encrypted database access and key validation.
Add opt-in encryption at rest for all local Turso database shards using @tursodatabase/database. Load encryption keys securely through env:// or configuration values, never store keys in plaintext, and fail safely when a key is missing or invalid. Provide a recoverable migration path from existing unencrypted shards, including verified backups, staged conversion, rollback on failure, and tests for encrypted database access and key validation.