You are here:
How Salesforce Shield EKM Works
With External Key Management (EKM), customers designate and use an external key management service (KMS) to manage data encryption keys (DEKs) in Salesforce. These DEKs encrypt and decrypt data. When not in use, Salesforce stores DEKs in a wrapped (encrypted) state within Shield Platform Encryption's key cache. For any encrypt or decrypt operation, Shield Platform Encryption sends the wrapped DEK to the customer's external key service, which then unwraps it and securely returns it.
