KMS Integration
Native integration with your Key Management System, so the encryption keys governing sensitive personal data stay under your control.
Your Keys, Your Custody
The DPDP Act expects reasonable security safeguards. Keeping key control in your KMS is one of the clearest ways to show it.
Bring Your Own Key
Connect AWS KMS, Azure Key Vault, GCP KMS or an on-premise HSM and keep custody of the master key.
Envelope Encryption
Data keys encrypt the records; the KMS wraps the data keys, so plaintext keys never rest in the database.
Automated Rotation
Rotate keys on a schedule or on demand, with re-wrapping handled without downtime or data re-entry.
Per-Tenant Keys
Isolate key material by tenant, entity or region to meet contractual and data-residency requirements.
Key Access Logging
Every decrypt call is logged, giving you a usage trail alongside the KMS provider's own audit log.
Revocation Kill-Switch
Disable a key to render its ciphertext unusable — a hard stop for incident response and offboarding.
How KMS Integration Works
Connect Your KMS
Register your key provider and grant a scoped role that can wrap and unwrap data keys only.
Map Keys to Data
Assign keys per tenant, purpose or region so sensitive fields are encrypted under the right key.
Rotate & Monitor
Schedule rotation, watch decrypt activity and revoke a key instantly if an incident demands it.
Keep Key Custody Where It Belongs
Connect your existing KMS and encrypt personal data under keys only your organisation can unlock.