Bring Your Own Encryption Key (BYOK) secures your Salesforce marketing database with an encryption key you manage, so that you can revoke access to your Account Engagement data in an emergency. No one has access to this key–not even Salesforce–so after access is removed, the data becomes unreadable.
To access Salesforce BYOK for Account Engagement, contact your Account Executive. Bring Your Own Encryption Key is only available with Marketing Cloud Account Engagement Premium Edition.
As a prerequisite to enabling Bring Your Own Key (BYOK), you must first create a multi-region Key*. Once created, reach out to your Salesforce Account team to request the key's implementation with your Account Engagement business unit. Within 4 business weeks, check for a notification from Account Engagement that the business unit has been set up with the key.
Here are the configuration details to include during key setup.
*Important: It’s critical that you configure the multi-region setting properly since you can’t change it later.
Primary Key Configuration Details
Multi-Region: us-east-1
Key Type: Symmetric
Key Material Origin: KMS
Rotation Frequency: Yearly
Key Policy to Add:
{
"Sid": "Allow use of the key",
"Effect": "Allow",
"Principal": {
"AWS": [
"arn:aws:iam::364709603225:role/delegated-sa_terraformer",
"arn:aws:iam::364709603225:role/delegated-administrator",
"arn:aws:iam::364709603225:role/pardot-mysql-backup-pi0-role",
"arn:aws:iam::680213136557:role/pardot-backups-replication-role"
]
},
"Action": [
"kms:Encrypt",
"kms:Decrypt",
"kms:ReEncrypt*",
"kms:GenerateDataKey*",
"kms:DescribeKey"
],
"Resource": "*"
}
{
"Sid": "Allow attachment of persistent resources",
"Effect": "Allow",
"Principal": {
"AWS": [
"arn:aws:iam::364709603225:role/delegated-sa_terraformer",
"arn:aws:iam::364709603225:role/delegated-administrator",
"arn:aws:iam::364709603225:role/pardot-mysql-backup-pi0-role"
]
},
"Action": [
"kms:CreateGrant",
"kms:ListGrants",
"kms:RevokeGrant"
],
"Resource": "*",
"Condition": {
"Bool": {
"kms:GrantIsForAWSResource": "true"
}
}
}
Secondary Key Configuration Details
Multi-Region: us-west-2
Key Type: Symmetric
Key Material Origin: KMS
Rotation Frequency: Yearly
Key Policy to Add:
{
"Sid": "Allow use of the key",
"Effect": "Allow",
"Principal": {
"AWS": [
"arn:aws:iam::364709603225:role/delegated-sa_terraformer",
"arn:aws:iam::364709603225:role/delegated-administrator",
"arn:aws:iam::364709603225:role/pardot-mysql-backup-pi0-role",
"arn:aws:iam::680213136557:role/pardot-backups-replication-role"
]
},
"Action": [
"kms:Encrypt",
"kms:Decrypt",
"kms:ReEncrypt*",
"kms:GenerateDataKey*",
"kms:DescribeKey"
],
"Resource": "*"
}
{
"Sid": "Allow attachment of persistent resources",
"Effect": "Allow",
"Principal": {
"AWS": [
"arn:aws:iam::364709603225:role/delegated-sa_terraformer",
"arn:aws:iam::364709603225:role/delegated-administrator",
"arn:aws:iam::364709603225:role/pardot-mysql-backup-pi0-role"
]
},
"Action": [
"kms:CreateGrant",
"kms:ListGrants",
"kms:RevokeGrant"
],
"Resource": "*",
"Condition": {
"Bool": {
"kms:GrantIsForAWSResource": "true"
}
}
}
Bring Your Own Key (BYOK) encrypts your Salesforce Account Engagement database, which includes the bulk of your data. For example, visitors, prospects, campaigns, and external activities are encrypted.
BYOK excludes some metadata required for access, such as user information. It also doesn’t encrypt data transmitted outside of Account Engagement or to other Salesforce products.
To avoid delays, provision your business unit before you request a Bring Your Own Key (BYOK) configuration.
Reach out to your Salesforce account team to get the process started. Be prepared with the following:
Important: Only revoke your key in case of an emergency, as the revoked data isn’t recoverable.
Revoke access to the key in your Amazon Web Services account’s Key Management Service. Within 30 minutes of revoking access, your Account Engagement application becomes unavailable, and the data is no longer accessible.
Revoking a key notifies the Salesforce Account Engagement team to shut down your business unit. If you revoke the key, the business unit becomes unavailable, and you risk permanent data loss.
If you set up the Salesforce BYOK according to these suggestions, the key rotates annually by default. If an error is detected in the rotation, an email will be sent to the person responsible for maintaining your key.
If you want to restore data from previous backups, retain your old keys. You have up to 90 days to restore data. If you lose your keys, all data is lost permanently.
000396854

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.