states that "[Cloud Connect] tenants can encrypt backups created with backup jobs, backup copy and replication jobs."
But "encryption works at the source side (unless you run a backup copy job via WAN accelerators)" in https://helpcenter.veeam.com/docs/backup/vsphere/data_encryption.html?ver=95
implies that encryption of backup files occurs at the target side. Does the target/Cloud Connect provider WAN accelerator perform the encryption of the backup files? If so does it retain the encryption key permanently? Or does the source/client WAN accelerator provide the encryption key to the target/Cloud Connect provider WAN accelerator only when needed?