BYOK - Customer Managed Keys
As a customer
I want to use my own keys to encrypt that data at rest
so that I could comply with regulatory requirements and have full ownership over my and my customers' data.
-
We see prospects with strict requirement for BYOK. Using GCP HSM-CMEK in their architecture .
Service: Kafka(Edited by admin) -
All of the actual customer discussions I have had were met by BYOC versus BYOK. The challenge with BYOK implementations is that the customer, per Ted's comment, do not want the provider to have the key at all. This is impossible with a fully managed service versus a self-managed service. With these implementations (fully managed) the provider must have the key to be able to decrypt a backup and restore a service.
-
absolute requirement for any regulated industries and the majority of enterprise customers are or have adopted this standard.
(Edited by admin)