Loading

Provision Bring Your Own Encryption Key for Salesforce Account Engagement

Julkaisupäivä: Aug 3, 2026
Kuvaus

Bring Your Own Encryption Key (BYOK) secures your Salesforce marketing database with an encryption key you manage, so that you can revoke access to your Account Engagement data in an emergency. No one has access to this key–not even Salesforce–so after access is removed, the data becomes unreadable.

Ratkaisu

How do I purchase Bring Your Own Key (BYOK)?

To access Salesforce BYOK for Account Engagement, contact your Account Executive. Bring Your Own Encryption Key is only available with Marketing Cloud Account Engagement Premium Edition.

How do I set up an encryption key?

As a prerequisite to enabling Bring Your Own Key (BYOK), you must first create a multi-region Key*. Once created, reach out to your Salesforce Account team to request the key's implementation with your Account Engagement business unit. Within 4 business weeks, check for a notification from Account Engagement that the business unit has been set up with the key.

 Here are the configuration details to include during key setup.

 *Important: It’s critical that you configure the multi-region setting properly since you can’t change it later.

 Primary Key Configuration Details

Multi-Region: us-east-1

Key Type: Symmetric

Key Material Origin: KMS

Rotation Frequency: Yearly

Key Policy to Add:
 

{
           "Sid": "Allow use of the key",
           "Effect": "Allow",
           "Principal": {
               "AWS": [
                   "arn:aws:iam::364709603225:role/delegated-sa_terraformer",
                   "arn:aws:iam::364709603225:role/delegated-administrator",
                   "arn:aws:iam::364709603225:role/pardot-mysql-backup-pi0-role",
                   "arn:aws:iam::680213136557:role/pardot-backups-replication-role"
               ]
           },
           "Action": [
               "kms:Encrypt",
               "kms:Decrypt",
               "kms:ReEncrypt*",
               "kms:GenerateDataKey*",
               "kms:DescribeKey"
           ],
           "Resource": "*"
       }
       {
           "Sid": "Allow attachment of persistent resources",
           "Effect": "Allow",
           "Principal": {
               "AWS": [
                   "arn:aws:iam::364709603225:role/delegated-sa_terraformer",
                   "arn:aws:iam::364709603225:role/delegated-administrator",
"arn:aws:iam::364709603225:role/pardot-mysql-backup-pi0-role"                ]            },            "Action": [                "kms:CreateGrant",                "kms:ListGrants",                "kms:RevokeGrant"            ],            "Resource": "*",            "Condition": {                "Bool": {                    "kms:GrantIsForAWSResource": "true"                }            }        }


 

Secondary Key Configuration Details

Multi-Region: us-west-2

Key Type: Symmetric

Key Material Origin: KMS

Rotation Frequency: Yearly

Key Policy to Add:
 

{
           "Sid": "Allow use of the key",
           "Effect": "Allow",
           "Principal": {
               "AWS": [
                   "arn:aws:iam::364709603225:role/delegated-sa_terraformer",
                   "arn:aws:iam::364709603225:role/delegated-administrator",
                   "arn:aws:iam::364709603225:role/pardot-mysql-backup-pi0-role",
                   "arn:aws:iam::680213136557:role/pardot-backups-replication-role"
               ]
           },
           "Action": [
               "kms:Encrypt",
               "kms:Decrypt",
               "kms:ReEncrypt*",
               "kms:GenerateDataKey*",
               "kms:DescribeKey"
           ],
           "Resource": "*"
       }
       {
           "Sid": "Allow attachment of persistent resources",
           "Effect": "Allow",
           "Principal": {
               "AWS": [
                   "arn:aws:iam::364709603225:role/delegated-sa_terraformer",
                   "arn:aws:iam::364709603225:role/delegated-administrator",
"arn:aws:iam::364709603225:role/pardot-mysql-backup-pi0-role"                ]            },            "Action": [                "kms:CreateGrant",                "kms:ListGrants",                "kms:RevokeGrant"            ],            "Resource": "*",            "Condition": {                "Bool": {                    "kms:GrantIsForAWSResource": "true"                }            }        }

 

What data is included in my key?

Bring Your Own Key (BYOK) encrypts your Salesforce Account Engagement database, which includes the bulk of your data. For example, visitors, prospects, campaigns, and external activities are encrypted.

BYOK excludes some metadata required for access, such as user information. It also doesn’t encrypt data transmitted outside of Account Engagement or to other Salesforce products.

How do I request my Salesforce BYOK implementation?

To avoid delays, provision your business unit before you request a Bring Your Own Key (BYOK) configuration.
 

Reach out to your Salesforce account team to get the process started. Be prepared with the following:

  • Salesforce Org ID
  • Business Unit ID
  • ARN Number (i.e. certificate identifier)
  • Full name and email address of the person responsible for maintaining your key

How do I revoke my key?

Important: Only revoke your key in case of an emergency, as the revoked data isn’t recoverable.

Revoke access to the key in your Amazon Web Services account’s Key Management Service. Within 30 minutes of revoking access, your Account Engagement application becomes unavailable, and the data is no longer accessible.

Revoking a key notifies the Salesforce Account Engagement team to shut down your business unit. If you revoke the key, the business unit becomes unavailable, and you risk permanent data loss.

How do I manage key rotation?

If you set up the Salesforce BYOK according to these suggestions, the key rotates annually by default. If an error is detected in the rotation, an email will be sent to the person responsible for maintaining your key.

If you want to restore data from previous backups, retain your old keys. You have up to 90 days to restore data. If you lose your keys, all data is lost permanently.

Knowledge-artikkelin numero

000396854

 
Ladataan
Salesforce Help | Article