BYOK can be included when the deployment model is compatible with the customer KMS or HSM. Integration, key scope and revocation effects are defined during technical assessment.
Ownership, permissions and responsibilities for the key are documented in the technical design.
Provider, algorithms, rotation and availability are assessed for the contracted environment.
Available logs and audit trails depend on the components and controls defined in the architecture.
Architecture and Security select a compatible KMS or HSM with the customer and define the permissions and responsibility model.
The design documents which data uses the key, how integration works and which rotation and revocation policies apply.
Before production, revocation and recovery behavior and the available evidence are validated in the contracted environment.