Externally Manage and Store Oracle Cloud Infrastructure Keys

Control your data and encryption keys for digital sovereignty and meet compliance requirements

  • Meet compliance mandates such as PCI DSS, GDPR, and CCPA
  • Streamline encryption management with seamless key rotation
  • Reduce administration costs with centralized key and policy management
  • Optionally store encryption keys in FIPS 140-2 Level 3 hardware security module
Oracle HYOK

Oracle Cloud Infrastructure (OCI) External Key Management Service (EKMS) is a new capability that allows customers to protect their data in OCI using encryption keys held inside CipherTrust Manager external to OCI.


  • Move critical workloads with sensitive data to Oracle Cloud Infrastructure
  • Maintain sovereign control of sensitive data
  • Gain strong key control and security
Oracle Cloud Infrastructure

OCI EKMS with Thales CipherTrust

CipherTrust Cloud Key Management (CCKM), which is a licensed component of the CipherTrust Manager, delivers external key storage, key generation, separation of duties, reporting, and key life cycle management to help fulfill internal and industry data security mandates. FIPS140-2 Level 3 certification available.

Enabling Organizations To:

  • Maximize choice from a single console, manage Native, BYOK, HYOK keys across clouds
  • Demonstrate compliance with privacy regulations such as GDPR, Shrems II, PCI-DSS, CCPA
  • Improve operational sovereignty to protect against internal and external bad actors
  • Reduce threat surface by centralizing control of keys outside of cloud providers
  • Increase efficiency and reduce costs by simplifying and automating key management
  • Faster time to value by speeding up migration to the cloud
OCI Console

We’re dedicated to making Oracle Cloud the most seamless and secure environment for customers in highly regulated regions and industries. Our EU Sovereign Cloud enables us to support EMEA customers in their data sovereignty strategies, and the HYOK integration with Thales is an integral part of our ability to support these compliance needs. This partnership will also greatly benefit U.S. customers in industries like financial services, allowing them to take full advantage of Oracle Cloud offerings with the privacy and security add-ons of Thales’ HYOK capabilities."
Mahesh Thiagarajan Senior Vice President, Software Development Oracle Cloud Infrastructure

CipherTrust Cloud Key Management

Amplify the benefits of your native keys. CipherTrust Cloud Key Management (CCKM) respects your choice to use native keys, while providing the opportunity to expand your key ownership models to include BYOK and HYOK. CCKM centralizes key management for Native, BYOK and HYOK cloud keys from a single browser window, across multiple clouds, regions, accounts, subscriptions, projects, applications, org ids and more.

Get the Product Brief

Get Up and Running in 3 Easy Steps

Icon 1

Get CipherTrust Manager Community Edition

Launch from Cloud Service Providers Google Cloud, Microsoft Azure or AWS, or download an OVA, HyperV or OpenStack.

Icon 2

Configure CipherTrust Manager

Follow the steps in our documentation to complete set up.

Icon 3

Deploy Your CCKM Free Trial