SECURITY · BRING YOUR OWN KEY

Bring Your Own Key

BYOK can be included when the deployment model is compatible with the customer KMS or HSM. Integration, key scope and revocation effects are defined during technical assessment.

Key management/customer · agreed integration
Providers/compatible KMS or HSM
Controls/defined in the architecture
01

Customer governance

Ownership, permissions and responsibilities for the key are documented in the technical design.

02

Compatible integration

Provider, algorithms, rotation and availability are assessed for the contracted environment.

03

Usage evidence

Available logs and audit trails depend on the components and controls defined in the architecture.

How BYOK
is defined

Architecture and Security select a compatible KMS or HSM with the customer and define the permissions and responsibility model.

The design documents which data uses the key, how integration works and which rotation and revocation policies apply.

Before production, revocation and recovery behavior and the available evidence are validated in the contracted environment.

Especificações
Master keyManaged by the customer
ProvidersKMS or HSM subject to assessment
EncryptionControls according to the architecture
RevocationImpact validated per deployment
AuditEvidence from contracted components

Which critical journey
needs more clarity now?