Encryption at Rest Configuration
Default Encryption
All data stored in the platform is encrypted at rest using AES-256-GCM by default. Each record is encrypted with a unique data encryption key (DEK), and DEKs are encrypted with a key encryption key (KEK) managed by our internal key management service. This envelope encryption pattern ensures that a compromise of any single key does not expose all stored data.
Default encryption uses platform-managed keys that are automatically rotated every 90 days. No configuration is required for default encryption. All API responses indicate the encryption status of returned data in the X-Encryption-Status response header.
Customer-Managed Keys (BYOK)
Enterprise plans support customer-managed encryption keys (BYOK) through AWS KMS, Google Cloud KMS, or Azure Key Vault integration. Your KMS key serves as the root key encryption key, giving you full control over the encryption lifecycle. If you disable or delete your KMS key, all data encrypted with it becomes inaccessible.
Configure BYOK by providing your KMS key ARN or resource ID in the organization settings: PUT /org/settings/encryption with {"kms_provider": "aws", "key_arn": "arn:aws:kms:us-east-1:123456789:key/your-key-id"}. The platform validates access to the key by performing a test encrypt/decrypt operation. Ensure the platform's service role has kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey permissions on your key.
Key Rotation
For customer-managed keys, enable automatic rotation in your KMS provider (recommended: annual rotation). When the KMS key is rotated, new data is encrypted with the new key version, and existing data is re-encrypted on the next read-modify-write operation. You can force immediate re-encryption of all data by calling POST /org/settings/encryption/rekey.
The rekey operation runs asynchronously and may take several hours for large datasets. Monitor progress via GET /org/settings/encryption/rekey-status. During rekeying, both old and new key versions must remain active in your KMS. Do not delete old key versions until the rekey operation completes and you have verified all data is accessible.
Cite this article: SecureAgent Research, 2025. Data available at the URLs referenced above.