Loading

Quip Enterprise Key Management (EKM) Setup Guide

Udgivelsesdato: Sep 24, 2026
Beskrivelse

Quip Enterprise Key Management (EKM) gives your organization control over the encryption keys used to protect all Quip content. With EKM enabled, Quip encrypts content using keys that you manage through Amazon Key Management Service (KMS) — an AWS service for creating and controlling encryption keys. Quip cannot decrypt your content without explicit access through those keys. This article walks through the complete EKM setup process, from initial rollout planning through ongoing key management operations.

Løsning

Before You Begin

EKM requires advance planning and coordination with your Quip account representative. Contact your Quip representative before starting to define a rollout plan, schedule, and testing approach. EKM is available for Quip Enterprise customers only.

Example: A healthcare company with HIPAA obligations enables EKM so their security team can demonstrate to auditors that Quip content is encrypted with company-controlled keys — and that access can be revoked immediately if needed, giving them full control over their data lifecycle.
 

Step 1: Plan Your Rollout

Work with your Quip representative to define:
  • Rollout scope: Whether to encrypt only new content first, gradually ramp to a percentage of content, or encrypt all existing content simultaneously
  • Timeline: EKM deployment length depends on your site size and testing requirements
  • Testing plan: Define how you will verify that encryption is working correctly before enabling it for all users

Step 2: Create Your Encryption Keys in Amazon KMS

  1. Set up Amazon KMS (Key Management Service) — an AWS service that creates and stores your encryption keys. See the Amazon KMS Product Overview and Getting Started Guide for setup instructions. Alternatively, use AWS CloudHSM via KMS Custom Key Store for a higher level of key control.
  2. Create three Customer Master Keys (CMKs) in Amazon KMS — a primary key and two backup keys. Unless you're setting up EKM for a VPC, create them in these regions: Primary Key in us-west-2, Backup Key 1 in us-east-2, Backup Key 2 in us-west-1. (VPC deployments should work with your Quip representative to choose the correct regions.)
  3. For each key, follow the KMS Create Keys guide. In the "Define Key Usage Permissions" step, scroll to "Other AWS Accounts," click "Add another AWS account," and enter the Quip AWS account number. This grants Quip's IAM role permission to send encrypted material to your keys and get decrypted material back via the AWS KMS APIs — it does not grant direct access to, or management/deletion rights over, your keys.

Step 3: Start Setup in the Admin Console


Once your deployment plan is in place and your three keys are created:
  1. Go to the Shield Advanced Security tab in your admin console.
  2. Click "Begin Setup" under the Enterprise Key Management heading, and confirm you understand the process.
  3. Enter the ARNs of your three keys (found in the AWS KMS console under "Customer managed keys" → each key's page, starting with arn:aws:kms), then click Next.
  4. Double-check everything, then click "Begin Setup" to kick off encryption according to your deployment plan.

Step 4: Key Rotation

Amazon KMS supports automatic annual key rotation. When a key is rotated, KMS creates a new key version and uses it for all future encryption operations; content encrypted with the previous version remains accessible, since KMS retains old versions for decryption.
To manually rotate a key outside the automatic schedule, create a new CMK, update the ARN provided to Quip via the Shield Advanced Security tab, and coordinate with your Quip representative to re-encrypt your content with the new key. Repeat for all three keys as needed.
 

Step 5: Key Revocation

Revoking access to a single document
Prevents everyone — all users, Quip employees, and the Quip service — from decrypting that specific document, while the rest of your content stays fully accessible.

  1. In the Shield Advanced Security tab, click "Get Document ID" and paste in the document's URL. Save the returned Document ID somewhere outside Quip — you'll need it to restore access later, and the lookup won't work once access is revoked.
  2. In the AWS KMS console, click on one of your keys, scroll to "Key Policy," and click Edit. Paste in this policy:
 
{ "Sid": "Deny decryption access to a specific document", "Effect": "Deny", "Principal": { "AWS": "arn:aws:iam::QUIP_AWS_ACCOUNT:root" }, "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey" ], "Resource": "*", "Condition": { "ForAnyValue:StringEquals": { "kms:EncryptionContext:RootID": "DOCUMENT_ID" } } }


- Replace `QUIP_AWS_ACCOUNT` with the same account number you were granted access to during setup. You can also find it in the existing "Allow use of key" statement in your Key Policy — the Principal line just below it has the account number. - Replace `DOCUMENT_ID` with your Document ID. - Optionally, edit the `Sid` to reference the document name, e.g. `"Sid": "Deny decryption access to doc '2020 Financials'"`. - Save the policy.
  1. Repeat step 2 for each of your three keys.
  2. Back in the Shield Advanced Security tab, click "Clear Document," enter the Document ID, and click "Clear Downloads" to purge it from caches and downloads.
  3. To restore access, delete the added policy from each key's Key Policy and use the Clear Document flow again to force the change through.



Revoking access to the entire site

Prevents everyone from decrypting any content — an emergency operation for data breach scenarios or immediate service termination. Contact your Quip representative before revoking to understand the impact on active users and pending migrations.

  1. Disable all three customer-managed keys in AWS KMS.
  2. In the Shield Advanced Security tab, scroll to "Clear Downloads" and click "Clear Site" to immediately purge content from all caches, search indices, and downloaded apps.
  3. To restore access, re-enable your keys and click "Clear Site" again to force the settings to take effect immediately.
Vidensartikelnummer

000380927

 
Indlæser
Salesforce Help | Article