Data security
Do you support customer-managed encryption keys (BYOK)?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
State whether customers can bring or manage their own encryption keys and, if so, how key access and revocation work. BYOK lets customers cut off access to their data by controlling the key.What the security reviewer is checking
BYOK questions come from buyers who want cryptographic control — the ability to revoke a key and render their data unreadable to the vendor — or who face regulatory expectations for key custody. Reviewers distinguish real BYOK (customer-held keys in their own KMS, referenced by your platform via key grants) from marketing BYOK (you generate a key "for" the customer inside your own KMS). If you do not support it, they check whether you say so honestly and what compensating controls exist: per-tenant key separation, envelope encryption, restricted key-usage IAM, and audit logging of key operations. Overclaiming here is easily exposed by one technical follow-up about revocation behavior.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.We do not currently offer customer-managed keys, and we prefer to answer that precisely rather than stretch the term. All customer data is encrypted at rest with AES-256 using envelope encryption: data keys are wrapped by master keys in our cloud KMS, with per-tenant key separation so each organization’s data is encrypted under distinct data keys. Key usage is restricted by IAM to the specific services that need it, no human has direct decrypt permissions, and every key operation is captured in KMS audit logs. Master keys rotate automatically on an annual schedule. True BYOK — where your organization holds the master key in your own KMS, grants our platform usage rights, and can unilaterally revoke access — is on our product roadmap, prioritized by enterprise demand; we are glad to discuss timelines under NDA. If your requirement is driven by a specific regulation, we can walk through how our current key architecture and audit evidence address it.
Evidence reviewers expect you to attach
- Encryption and key management standard describing the envelope encryption design
- KMS configuration summary showing per-tenant key separation and rotation
- IAM policy summary restricting decrypt operations to services, not people
- Product roadmap statement on BYOK, if shareable under NDA
Follow-up questions reviewers ask next
- If BYOK were supported, what data would it cover — everything or select stores?
- What happens operationally when a customer revokes their key?
- Are per-tenant keys truly distinct, or is one master key shared across tenants?
- Can we receive KMS audit log evidence for key operations affecting our data?
- What is the realistic timeline for BYOK availability?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated data security questions
Do you encrypt data at rest and in transit?How do you handle customer data deletion requests?Do you maintain an inventory of all customer data?What is your data backup and recovery process?How do you secure data in development environments?Do you have a privacy policy that covers customer data usage?
Browse the full security questionnaire question library