Loading
Set Up and Maintain Your Salesforce Organization
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Take Good Care of Your BYOK Keys

          Take Good Care of Your BYOK Keys

          When you create and store your own key material outside of Salesforce, it’s important that you safeguard that key material. Make sure that you have a trustworthy place to archive your key material; never save a tenant secret or data encryption key on a hard drive without a backup.

          Required Editions

          Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.
          Available in: Enterprise, Performance, and Unlimited Editions with the Salesforce Shield or Shield Platform Encryption licenses.
          Available for free in Developer Edition.

          Back up all imported key material after you upload them to Salesforce. Backing it up ensures that you have copies of your active key material. See Back Up Your Tenant Secret in Salesforce Help.

          Review your company policy on key rotation. You can rotate and update your keys on your own schedule. See Rotate Your Encryption Keys.

          Warning
          Warning You are solely responsible for making sure that your data and key material are backed up and stored in a safe place. Also, due to rotation, over time you will accumulate a number of keys. You should back them up into source control, and keep an up-to-date registry of your keys outside of Salesforce. Salesforce can’t help you with deleted, destroyed, or misplaced tenant secrets and keys. Even if you destroy a key in your Salesforce org, we strongly encourage you to preserve your backup copy in source control.
           
          Loading
          Salesforce Help | Article