You are here:
Encrypt Data 360 with Customer-Managed Root Keys
By default, Salesforce encrypts all Data 360 data at rest with a Salesforce-managed data encryption key (DEK). With Platform Encryption for Data 360, you can generate and control a Data 360 root key in Salesforce. Your Data 360 root keys are specific to your org and secure the DEKs that encrypt and decrypt your data. In this way, you control the chain of keys that encrypt your data. If you want to generate or manage keys outside of Salesforce, you can also use Bring Your Own Key (BYOK) or Shield External Key Management (EKM).
