Integration (v100.39.0+)

Encryption Settings

Starting with v100.39.0, you can configure encryption for your organization using your own key management service, commonly referred to as Bring Your Own Key (BYOK). This feature gives you full control over your encryption keys and helps to meet compliance requirements for data protection regulations such as HIPAA and GDPR.

Manage encryption using your own key

Use this card to set up data encryption and review its details. Encryption is managed through a Key Management Service (KMS)—a secure system that creates and controls cryptographic keys.

Important note

You need the "Manage encryption settings" role to configure BYOK.

Configure KMS authentication to set up encryption

1

Click Add

2

Select the KMS type (Azure Key Vault is the default)

3

Enter the required details:

  • Client Id

  • Tenant Id

  • Client Secret

  • Key URL

4

Click Test and Save to validate credentials

5

Once validated, select your key and confirm the encryption algorithm

6

Click Confirm

After saving, the encryption status for the KMS will display as Enabled, along with details like KMS type, date added, and key URL.

Secret expiration is monitored. If expiration is less than 30 days:

  • A warning appears in Organization settings

  • Weekly reminders are sent to your organization's point of contact until updated

Last updated

Was this helpful?