KMS Integration

Native integration with your Key Management System, so the encryption keys governing sensitive personal data stay under your control.

Your Keys, Your Custody

The DPDP Act expects reasonable security safeguards. Keeping key control in your KMS is one of the clearest ways to show it.

Bring Your Own Key

Connect AWS KMS, Azure Key Vault, GCP KMS or an on-premise HSM and keep custody of the master key.

Envelope Encryption

Data keys encrypt the records; the KMS wraps the data keys, so plaintext keys never rest in the database.

Automated Rotation

Rotate keys on a schedule or on demand, with re-wrapping handled without downtime or data re-entry.

Per-Tenant Keys

Isolate key material by tenant, entity or region to meet contractual and data-residency requirements.

Key Access Logging

Every decrypt call is logged, giving you a usage trail alongside the KMS provider's own audit log.

Revocation Kill-Switch

Disable a key to render its ciphertext unusable — a hard stop for incident response and offboarding.

How KMS Integration Works

1

Connect Your KMS

Register your key provider and grant a scoped role that can wrap and unwrap data keys only.

2

Map Keys to Data

Assign keys per tenant, purpose or region so sensitive fields are encrypted under the right key.

3

Rotate & Monitor

Schedule rotation, watch decrypt activity and revoke a key instantly if an incident demands it.

Keep Key Custody Where It Belongs

Connect your existing KMS and encrypt personal data under keys only your organisation can unlock.