BYOK is now available: take full control of your encryption keys
We've been working on this one for a while, and we're glad to say it's here. Bring your own key vault gives MSPs and their customers complete sovereignty over encryption keys, so only they decide who can access their data, regardless of what happens with any cloud provider. No shared responsibility. No vendor dependency. Just full, verifiable control.
Why this matters now
Data sovereignty has shifted from a nice-to-have to a baseline expectation. Customers in regulated industries are increasingly asking hard questions about who holds the keys to their data, and "the platform manages it" is no longer a sufficient answer. At the same time, high-profile cloud outages have made recovery independence a real operational concern, not just a theoretical one.
BYOK addresses both. When you control the keys, you control the data. And you stay recoverable even if a cloud provider goes down.
What's included
External KMS integration: connect Azure Key Vault or AWS KMS, or continue using CyberSentriq's built-in system key vault if that works better for your setup.
Encryption key export: securely export a master key as a recovery contingency if your KMS becomes inaccessible during a major outage or incident.
Per-customer configuration: configure BYOK at the individual customer level for flexible, granular control across your entire client base.
Works across Microsoft 365, Entra ID, and Google Workspace.
Ready to get started?
Follow the guide on how to switch your company KMS to get set up. If you have questions about the setup process or want to understand which KMS option is right for your environment, reach out to your account manager or drop a question in the comments below.
A huge thank you to the customers who worked alongside us during development. Your feedback shaped this feature as it evolved, and it's a better product for it. If you're already using BYOK or are planning to set it up, we'd love to hear how you're approaching it.