Plan requirement
| Subscription | Any plan |
| Also required | Advanced Data Privacy and Protection |
| Access | Admin |
Encryption with keys you control. What that changes, and the responsibility that comes with it.
What is already true
Your data is encrypted at rest and in transit as standard. This add-on is not the difference between encrypted and not encrypted.
What advanced encryption changes
Who holds the key. With key management under your control, access to the underlying data depends on a key you administer rather than one the platform holds alone.
That is the point, and it is what a security questionnaire is usually asking about.
What it protects against
Access to the stored data at the infrastructure level. It is a meaningful control for organisations that must demonstrate that specific separation.
What it does not protect against
Anything happening through the normal interface. An agent who can open a ticket sees the content; a compromised agent account still exposes what that account could reach.
Most real incidents are of that kind, which is why this is not a substitute for access hygiene.
The responsibility
Keys have to be managed: stored securely, rotated, and recoverable. Losing control of a key has consequences for your access to your own data, and that has to be planned rather than assumed.
Decide who owns it
Key management belongs with whoever handles it elsewhere in your organisation, usually IT security. It should not be a support admin's side responsibility.
Plan the setup
This is configuration with real consequences. Ask pluscloud support before starting and we will work through it with you.
Comments
0 comments
Article is closed for comments.