We should have an optional at-rest encryption method for private key data that is persisted in the storage.