Skip to main content
All CollectionsData backup and ArchivingBYOK
Gearset BYOK via AWS KMS for backup
Gearset BYOK via AWS KMS for backup

Find out the key differences between BYOK feature (for Enterprise licenses only), and Self-Service Encryption Key (for Starter licenses)

Rumyana Cherneva avatar
Written by Rumyana Cherneva
Updated yesterday

Overview

Gearset's backup solution stores your data in our AWS instance. We use Amazon Relational Database Service (RDS) and AWS Simple Storage Service (S3) to host the data.

The RDS and S3 instances are encrypted at rest using AWS KMS's (Key Management Service) generated team based encryption key provided to all customers by default.


Bring Your Own Key (BYOK) via AWS Key Management Service (AWS KMS) can offer you more control if you would like to be the one responsible for the access and management of your backup's encryption key.

Once you create a key and provide it to your Gearset's Account Executive, the data will be stored in a dedicated infrastructure encrypted by your key.

Who should use BYOK

License requirements:
BYOK feature is available only for customer on Backup Enterprise licenses.
​
If you're on Backup Starter license, your team can use Self-Service Encryption Key instead.

BYOK will help you meet strict regulatory controls that your organization might require in order for you to use our backup tool.

With BYOK, you will have full control of the lifespan of your encryption key. Deleting the key will result in your data becoming inaccessible to anyone.

You will also have full control of who is able to access the encryption key and the permissions associated with the key.

Considerations

BYOK is not needed for every organization. With BYOK, the key existence and maintenance will be solely your responsibility. Gearset will use your key for encrypting and decrypting the data.

A Gearset generated key may be more appropriate for your organization. Gearset generates a new master key for every unique team that uses backup. We have best practices around generating, storing and rotating keys. Your backup master key can be deleted by you at any time by navigating to Gearset account settings and looking at Data management.


Setting up BYOK for Backup at Gearset

Learn more about how to set up BYOK in this article:
​Setting up BYOK for Gearset backup using AWS KMS

Did this answer your question?