Shield Platform Encryption’s Bring Your Own Key (BYOK) feature gives you an extra layer
of protection against unauthorized access to critical data. It can also help you meet the
regulatory requirements that come with handling financial, health, or personal data. After you
set up your key material, use Shield Platform Encryption as you always do to encrypt data at
rest in your Salesforce org.
Required Editions
Available in both Salesforce Classic (not available in all orgs) and Lightning
Experience.
Available in: Enterprise, Performance, and Unlimited
Editions with the Salesforce Shield or Shield Platform Encryption licenses.
Available for free in Developer Edition.
With Shield Platform Encryption, you manage the lifecycle of your data encryption keys (DEKs)
while protecting these keys from unauthorized access. By controlling the lifecycle of your
organization’s tenant secrets, you control the lifecycle of the data encryption keys derived
from them. And for some encryption services you can opt out of key derivation altogether and
upload a final DEK.
By default, Salesforce derives DEKs from the primary secret and the tenant secret for use
during each encrypt and decrypt operation. Salesforce generates the primary secret with a
hardware security module (HSM) once per release during a High Assurance Virtual Ceremony.
While each key derivation process uses the same per-release primary secret, your tenant secret
or root key is unique to your org. You control when it’s generated, activated, revoked, or
destroyed. Salesforce doesn’t store derived DEKs.
You have four options for setting up your key material.
Use Shield Platform Encryption to generate org-specific key material.
Use the infrastructure of your choice, such as an on-premises HSM, to generate and manage
key material outside of Salesforce. Then upload that tenant secret to Salesforce. This
option is known as Bring Your Own Key. If the key material is a tenant secret,
you provide the tenant secret from which the key is derived. If you provide a root key, you
provide a key that securely wraps your encryption key.
Opt out of the Shield Platform Encryption key derivation process completely with the Bring
Your Own Key service. Use the infrastructure of your choice to create a DEK instead of a
tenant secret. Then upload this DEK to the regional Shield Key Management Service (KMS).
Shield Platform Encryption bypasses the derivation process and uses that DEK directly during
encrypt and decrypt operations. You can rotate customer-supplied DEKs the same way that you
rotate customer-supplied tenant secrets. BYOK is available for field-level encryption,
Database Encryption, search indexes, Backup & Recover Next, and Data 360. BYOK for
Backup & Recover Next and Data 360 supports only root key uploads. The other features
support DEK uploads only.
Generate and store key material outside of Salesforce by using the key service of your
choice. Then use either the Salesforce External Key Management Service or Salesforce
Cache-Only Key Service to fetch your key material on demand. Your key service transmits key
material over a secure channel that you configure. Salesforce then encrypts and stores it in
the cache for immediate encryption and decryption operations. Cache-Only Keys isn’t
available for Database Encryption.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.