Skip to main content

Does amaise support customer-owned encryption keys (BYOK)?

Written by amaise Support

Does amaise support customer-owned encryption keys (BYOK)?

Yes. Today, each workspace's documents are encrypted in S3 under a dedicated, amaise-managed AWS KMS key (FIPS-validated HSM backend, automatic annual rotation). Because each workspace has its own key, that workspace's documents can be crypto-shredded by disabling the key.

A compliance service monitors the entire lifecycle of the keys — it ensures that active tenants have an active key and that when a tenant is deleted, the associated key is decommissioned within the window defined by AWS KMS guidance.

For customers with special data sovereignty requirements, amaise offers customer-managed keys (BYOK) on request as a bespoke onboarding project in two variants: a customer-owned KMS key from the customer's own AWS account, or an external HSM via AWS External Key Store (XKS) with Securosys in Switzerland for CLOUD-Act-resistant Swiss sovereignty. Azure Key Vault and Azure Cloud HSM cannot be connected natively, as AWS KMS binds external keys only via XKS, which Azure does not implement. Contact us at [email protected] for details.

Did this answer your question?