You are here:
Work with External Key Material
So you can maintain more complete control over your key material, Salesforce offers you three options: BYOK (Bring Your Own Key), EKM (External Key Management), and the Cache-Only key service.
- Bring Your Own Key (BYOK)
When you supply your own key material, you take direct control over encryption keys in a way that helps you address compliance and regulatory requirements. You retain all the benefits built into Salesforce Shield Platform Encryption. You can upload your own customer-supplied keys for most data stores that Shield Platform Encryption supports. Depending on the feature, BYOK supports tenant secrets, data encryption keys (DEKs), and root keys. - External Key Management
Shield External Key Management (EKM) connects your Salesforce implementation to your key material in an external key management service (KMS). Shield Platform Encryption then uses that key material to encrypt and decrypt your Salesforce data. EKM fetches your keys on demand from the external KMS over a secure channel. - Cache-Only Key Service
Shield Platform Encryption’s Cache-Only Key Service addresses a unique need for non-persisted key material. You can store your key material outside of Salesforce in any key repository or service that you control and have the Cache-Only Key Service fetch your key on demand from that key service. Your key service transmits your key over a secure channel that you configure, and the Cache-Only Key Service uses your key for immediate encrypt and decrypt operations. Salesforce doesn’t retain or persist your cache-only keys in any system of record or backups. You can revoke key material at any time. - Configure Your Cache-Only Key Callout Connection
Use a named credential to specify the endpoint for your callout, and identify the key that you want to fetch from your endpoint.
