You are here:
Create AWS Key to Encrypt Your Data
If you have enabled Salesforce Files, add another layer of data protection and encrypt your data by using Amazon Web Services (AWS). Encrypt data by using your own keys.
Required Editions
| Available in: Unlimited Edition with Einstein Relationship Insights Basic |
| Available for an additional cost in: Enterprise, Performance, and Unlimited Editions |
Before you set up data encryption:
- Set up Salesforce Files. See Connecting with Salesforce Files.
- From the Einstein Relationship Insights component, copy the AWS region and AWS account ID. See Copy the AWS Region and AWS Account ID.
- Log in to your AWS console.
- Select the AWS region that matches the region on the Einstein Relationship Insights component settings page.
-
Create a key with an alias and key ID.
- In the search field, enter KMS, and then select Key Management Service.
- Click Create a key.
-
In the Configure key step, select the Symmetric key type and
the Encrypt and decrypt key usage.
To import externally managed key material, see Importing key material in AWS KMS keys.
- Click Next.
- In the Add labels step, add a unique alias for the KMS key, and click Next.
- In the Define key administrative permissions step, select an admin user.
- Select Allow the administrators to delete this key, and click Next.
- In the Define Key usage permissions step, under Other AWS accounts, click Add another AWS account, and paste the AWS account ID copied from the Einstein Relationship Insights component settings page.
- Click Next.
- In the Review step, review the key configuration and other details.
- Click Finish.
-
Copy the Alias ARN. Go to KMS | Customer-managed keys | Key. Click the Aliases tab, and then click
.
-
On the Einstein Relationship Insights component settings page, under Salesforce Files
content source, enter the AWS key or alias ARN.
Note We recommend that you enter the Alias ARN to ensure that the data key is updated during automatic key rotation.- Example of an AWS key:
arn:aws:kms:us-east-2:123412341234:key/9e09e569-b0c8-4e2c-8364-35eaef36341e - Example of an Alias ARN:
arn:aws:kms:us-east-2:123412341234:alias/example-alias-valuetesting
- Example of an AWS key:
- To automatically update your data keys during manual rotation, select Rotate Data Keys.
- Save your changes.
The Einstein Relationship Insights component shows the AWS KMS key, which can be used to encrypt your data.
- Copy the AWS Region and Account ID
Before you encrypt your data by using Amazon Web Services, copy the AWS region and account ID from the Einstein Relationship Insights component. - Automatic Re-Encryption of Data
If you enable automatic key rotation for your AWS Key Management Service (KMS) key, AWS rotates the root key material annually. During the root key rotation, the system rotates your data key, which is used to encrypt and re-encrypt the data.
Did this article solve your issue?
Let us know so we can improve!

