-werners-
Esteemed Contributor III

the spilled data is written to some object store on the cloud provider.

I believe all of them apply encryption by default.

Of course it is up to you (or your colleagues) to restrict access to the storage.​