Data Rooms Providers Find a data room
VDR glossary · Security

What are customer-managed encryption keys (BYOK)?

Definition

Customer-managed encryption keys (BYOK): An encryption setup in which the client, not the data room provider, creates and controls the keys that protect its stored files, and can revoke them to make the data unreadable.

How it works in a data room

Normally the provider generates and manages the keys used for encryption at rest. With customer-managed keys, often called bring your own key, the client creates a master key in its own cloud key management service or hardware module and grants the data room limited permission to use it. Every time a file is decrypted, the platform must ask that key service, and every request is logged on the client’s side. If the client disables or deletes the key, the stored content in the room becomes unreadable, including backups.

Why it matters in a deal

Banks, defense contractors, pharmaceutical groups and some public bodies have policies that forbid a third party from holding sole control over keys to their most sensitive records. For them, BYOK can decide whether a provider is allowed at all. It also gives a clear exit: when the project ends, revoking the key is a verifiable way to put the data out of reach. The trade-off is operational: a mistakenly deleted key can lock everyone out, so the client needs its own procedures. Expect it on enterprise contracts, which affects pricing and setup time.

Example

A German utility planning to sell a grid subsidiary requires that the keys protecting network maps stay in its own key vault. The selected provider connects to that vault, and the utility’s security team watches decryption requests during the first week to confirm the setup. When the room closes, they disable the key and file a note of the date. The Germany guide explains the wider data protection setting.

Related terms