Loading
Prepare for Email to Become the Default Login ExperienceRead More
Intermittent freezing when using using certain browser versionsRead More
Set Up and Maintain Your Salesforce Organization
Why Bring Your Own Key?

Why Bring Your Own Key?

Shield Platform Encryption’s Bring Your Own Key (BYOK) feature gives you an extra layer of protection against unauthorized access to critical data. It can also help you meet the regulatory requirements that come with handling financial, health, or personal data. After you set up your key material, use Shield Platform Encryption as you always do to encrypt data at rest in your Salesforce org.

Required Editions

Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.
Available in: Enterprise, Performance, and Unlimited Editions with the Salesforce Shield or Shield Platform Encryption licenses.
Available for free in Developer Edition.

With Shield Platform Encryption, you manage the lifecycle of your data encryption keys (DEKs) while protecting these keys from unauthorized access. By controlling the lifecycle of your organization’s tenant secrets, you control the lifecycle of the data encryption keys derived from them. And for some encryption services you can opt out of key derivation altogether and upload a final DEK.

By default, Salesforce derives DEKs from the primary secret and the tenant secret for use during each encrypt and decrypt operation. Salesforce generates the primary secret with a hardware security module (HSM) once per release during a High Assurance Virtual Ceremony. While each key derivation process uses the same per-release primary secret, your tenant secret or root key is unique to your org. You control when it’s generated, activated, revoked, or destroyed. Salesforce doesn’t store derived DEKs.

You have four options for setting up your key material.

  • Use Shield Platform Encryption to generate org-specific key material.
  • Use the infrastructure of your choice, such as an on-premises HSM, to generate and manage key material outside of Salesforce. Then upload that tenant secret to Salesforce. This option is known as Bring Your Own Key. If the key material is a tenant secret, you provide the tenant secret from which the key is derived. If you provide a root key, you provide a key that securely wraps your encryption key.
  • Opt out of the Shield Platform Encryption key derivation process completely with the Bring Your Own Key service. Use the infrastructure of your choice to create a DEK instead of a tenant secret. Then upload this DEK to the regional Shield Key Management Service (KMS). Shield Platform Encryption bypasses the derivation process and uses that DEK directly during encrypt and decrypt operations. You can rotate customer-supplied DEKs the same way that you rotate customer-supplied tenant secrets. BYOK is available for field-level encryption, Database Encryption, search indexes, Backup & Recover Next, and Data 360. BYOK for Backup & Recover Next and Data 360 supports only root key uploads. The other features support DEK uploads only.
  • Generate and store key material outside of Salesforce by using the key service of your choice. Then use either the Salesforce External Key Management Service or Salesforce Cache-Only Key Service to fetch your key material on demand. Your key service transmits key material over a secure channel that you configure. Salesforce then encrypts and stores it in the cache for immediate encryption and decryption operations. Cache-Only Keys isn’t available for Database Encryption.
 
Loading
Salesforce Help | Article