Proving that remotely stored data is encrypted at rest is hard, and in fact proving there is not an unencrypted copy is impossible. However, using a resource bound on the cloud provider (such as storage or computation), Hourglass can prove that files on disk are encrypted. Moreover, the system was designed such that keeping an additional, unencrypted copy, is more costly than only storing the encrypted version, using simple economics to encourage proper handling of a user's data.

