Tangentially related: what's state-of-the-art for data protection & access control for small organizations? One runs into the "someone's gotta be trusted with the master keys" problem there so early & often that all the "big" solutions feel silly. Do small shops just farm this out via SaaS and hope their provider's doing the right thing?<p>(the answer back in the day, and perhaps still, was just "they don't really worry about it at all, and hope nothing goes wrong")