Key Life Cycle Automation
With the click of a button or an API request, keys are marked for automated key rotation. From then on, CipherTrust Cloud Key Manager performs key rotation automatically with comprehensive logging for IT efficiency and enhanced data security. Key rotation may be specified for keys without expiration dates, or specifically for keys to be rotated prior to their expiration dates. Multiple schedules per cloud are available.
Strong Encryption Key Security
CipherTrust Cloud Key Manager leverages the security of CipherTrust Manager, Thales Luna Network HSM or the Vormetric Data Security Manager to create keys. Secure storage is provided for clouds that deliver backup keys which can mitigate accidental key deletion in cloud consoles. You control full key metadata control during upload and for keys in use.
True Multi-Cloud Support
With support for Amazon Web Services and AWS GovCloud, Microsoft Azure, Azure Stack, Azure GovCloud, the Azure China and Germany sovereign clouds, IBM Cloud, Google Cloud Platform, Salesforce.com plus SalesForce Sandbox as well as SalesForce GovCloud Plus, CipherTrust Cloud Key Manager keeps you in control of encrypted data across multiple clouds from a single pane of glass, including across multiple accounts. For example, CipherTrust Cloud Key Manager retrieves from the cloud provider the supported key types and then prevents upload of an incorrect key type. The solution is engineered to work with each cloud’s multi-account key management suites, including AWS inter-account key sharing and Azure “B2B” support.
Comprehensive Key Management
Deploy CipherTrust Cloud Key Manager with any number of keys already created at the cloud provider. Create cloud-native keys in the cloud console as needed. CipherTrust Cloud Key Manager will automatically synchronize, at intervals you can define, its key database with the provider’s. Key attributes such as expiration rules and usage options are all maintained. You can request creation of cloud-native keys, as well as upload BYOK-keys, from the CipherTrust Cloud Key Manager console. If cloud provider rotation rules for native keys are insufficient, you can rotate keys under the control of CipherTrust Cloud Key Manager.
CipherTrust Cloud Key Manager goes well beyond Cloud Bring Your Own Key: It is a comprehensive cloud key life cycle manager.
The Compliance Tools You Need
CipherTrust Cloud Key Manager has the full range of logs and reports you need for fast compliance reporting, including a per-cloud operational logs and a range of pre-packaged key activity reports.
Support for Emerging Technologies
With support for Salesforce.com cached keys, CipherTrust Cloud Key Manager adds Hold Your Own Key technology to BYOK. As a component of its RESTful APIs for the next level of automation, the product includes support for Azure Service Principle and AWS Assumed Role authentication mechanisms.