What I'm interested in is how should I encrypt and store sensitive user data on a server such that it is retrievable but secure.
Secure from remote but unskilled attackers using auto tools poorly?
Secure from remote but skilled users targetting your system?
Local and skilled users targetting your system?
Law enforcement smashing the door down?
Well formed legal documents?
Well funded government agencies?
Malicious employees?
It does help if a thief walks out with your server, or if some extremely uneducated and unprofessional law enforcement power down your server as they serve their warrant on your datacenter - but neither of those scenarios are anywhere near the top of the "reasons your sensitive data got compromised and showed up on pastebin" lists.