Skip to content

Set Up Key Management Service for Data Encryption

All new warehouses can be created with data at rest encryption enabled. There are two options for Key Management Services (KMS) behind the data encryption:

  • Actian-managed encryption
  • Your customer-managed KMS

These services use a master key encryptionkey to encrypt and decrypt a data encryption key for locking and unlocking the Actian warehouse.

Actian Data Platform supports the following external KMSs:

Actian Data Platform does not support external keys from Google Cloud Key Management or Microsoft Azure Key Vault.

Note

To use your external KMS for data encryption, you must set up the external key before creating any warehouses.

Important

IMPORTANT!Any warehouses created using the Actian-managed encryption key or your customer-managed external KMS master key always use that method for data key decryption. Once an encryption method is assigned at warehouse creation, it cannot be changed subsequently.