Feature × Audience

How does BYOK work for enterprise architects on Plugsky?

For architects the deliverable is a key hierarchy, a custody owner and an evidence path into the SIEM — designed before go-live, not retrofitted. Plugsky performs cryptographic operations with envelope encryption: your master key wraps per-object data keys, AES-256 protects data at rest with per-region KMS, TLS 1.3 protects it in transit, and revoking the key cuts access to protected data.

Key facts

Key custodyCustomer-managed keys via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM
EncryptionAES-256 at rest with envelope encryption and per-region KMS; TLS 1.3 in transit
RevocationRevoking the key cuts access to protected data — a live control you operate
DeploymentCloud, your VPC, on-prem and air-gapped tiers all support customer key custody
Access controlSSO (SAML 2.0 or OIDC), SCIM provisioning and RBAC at workspace, role and resource level
AuditKey lifecycle and access events exportable to SIEM (Splunk, Sentinel, QRadar, Datadog)
Reference architectureKey hierarchy documented per deployment tier; keys separated from platform admin
Exit pathRevoke or retire keys at offboarding; application code stays OpenAI-compatible

TL;DR

  • Your KMS or HSM holds the master key; revocation becomes a live control you operate.
  • Envelope encryption with AES-256 at rest and TLS 1.3 in transit keeps rotation cheap.
  • Document the key hierarchy before go-live; retrofitting custody is a project.
  • Separate key permissions from platform administration so no single role holds both.
  • Start free with plugsky-micro and plugsky-lite; a 14-day full-access trial covers larger models.

How it works, step by step

  1. Decide which stores fall under customer-managed keys and name the owner of the key lifecycle.
  2. Create the key in your KMS or HSM and reference it from the Plugsky workspace.
  3. Rehearse rotation and revocation in staging before any production data is protected.
  4. Draw the key hierarchy and assign an owner for the master key and each data key class.
  5. Decide the deployment tier per workload and confirm it supports your custody model.
  6. Export key lifecycle events to the SIEM and keep the runbook under change control.
1Decide which storesfall undercustomer-managed2Create the key inyour KMS or HSM andreference it from3Rehearse rotationand revocation instaging before any4Draw the keyhierarchy andassign an owner for5Decide thedeployment tier perworkload and6Export keylifecycle events tothe SIEM and keep

Try it yourself

Open the private LLM deployment estimator →

BYOK for enterprise architects: what changes

Enterprise architects are asked to prove that encryption keys are separable from the platform, that revocation is possible without vendor intervention, and that the control survives deployment changes. A reference architecture answers that with a key hierarchy, an identity model and an audit trail — not a checkbox on a security questionnaire.

BYOK means you supply and control the keys that protect your data — through a cloud KMS such as AWS KMS or Azure Key Vault, HashiCorp Vault, or an on-prem HSM — while Plugsky performs cryptographic operations with envelope encryption: a master key you own wraps the data keys that protect each store, so rotating or revoking a small key changes access without touching the corpus. AES-256 protects data at rest with per-region KMS, TLS 1.3 protects it in transit, and key permissions are separated from platform administration.

Architecture and controls

Diagram the key hierarchy first: which KMS or HSM holds the master key, which data keys wrap which stores, who can revoke, and what happens to running workloads when a key is disabled. Separate key permissions from platform administration, then route key lifecycle and access events into the SIEM you already operate.

Integration pattern and rollout

Start from the deployment topology you run — Plugsky cloud, your VPC, on-prem or air-gapped — and add key custody as a layer. Because the API stays OpenAI-compatible, key separation changes configuration, identity and operations rather than application code.

Integrate custody as configuration, not application code. A workspace references the key provider, your services keep using the same OpenAI-compatible endpoints, and the security team owns the key lifecycle: creation, rotation, revocation and evidence. Because the key hierarchy is external to the application, a change of custody does not change prompts, evaluations or SDK usage.

Limits, evidence and cost

Where BYOK does not help: it does not make an uncertified platform certified, and it does not remove your duty to classify data. Compliance posture shows SOC 2 Type II and ISO 27001 readiness in progress rather than completed certification — record that honestly in your risk register.

Pricing stays flat-rate on self-serve plans — see the live pricing page for current tiers — so key custody does not introduce per-operation billing. Start on the free plan with plugsky-micro and plugsky-lite and no card, then use the 14-day full-access trial to evaluate larger models before procurement.

Honest comparison

ConcernPlugsky BYOKVendor-managed keysBuilding in-house
Key custodyYour KMS or HSM; keys separated from platform administrationVendor KMS and shared control planeYou build and run the whole stack
RevocationRevoke the key and protected access stopsUsually a vendor support processYou own the runbook
EvidenceKey lifecycle and access events exportable to SIEMVendor portal logsCustom logging pipeline
Operational loadYou own key availability, rotation and backupsVendor owns the lifecycleYou own everything
Time to controlConfiguration on supported tiersAvailable immediatelyQuarters of engineering
Reference architectureKey separation documented per deployment tierVaries by vendorYou design and prove it

Frequently asked questions

What does BYOK actually change?

You supply and control the master key through a KMS or HSM while Plugsky performs cryptographic operations with envelope encryption. Revoking your key stops access to protected data, and key operations stay auditable.

Who is responsible when a key is unavailable?

You are. Key availability becomes your availability, so plan KMS or HSM redundancy, break-glass procedures and incident response before go-live.

Does BYOK replace certification or a DPA?

No. It is one technical control. Compliance posture — SOC 2 Type II and ISO 27001 readiness in progress — and contractual terms such as the DPA must be reviewed separately.

Does BYOK change our application code?

No. Key custody is configuration on supported tiers and the API stays OpenAI-compatible, so application code, prompts and evaluations carry over unchanged.

How should we document BYOK for audits?

Diagram the key hierarchy, record who can revoke or rotate, and export key lifecycle events to your SIEM. Keep the runbook under the same change control as other critical procedures.

Can we rotate keys without downtime?

Use envelope encryption so rotation targets small data keys rather than the master key, and rehearse the rotation in staging first — the operational path is where incidents concentrate.