Feature × Audience

How does BYOK work for government teams on Plugsky?

For government, custody must be sovereign and provable: master keys under national control, dual control for revocation, and audit evidence that survives procurement review. Plugsky performs cryptographic operations with envelope encryption: your master key wraps per-object data keys, AES-256 protects data at rest with per-region KMS, TLS 1.3 protects it in transit, and revoking the key cuts access to protected data.

Key facts

Key custodyCustomer-managed keys via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM
EncryptionAES-256 at rest with envelope encryption and per-region KMS; TLS 1.3 in transit
RevocationRevoking the key cuts access to protected data — a live control you operate
DeploymentCloud, your VPC, on-prem and air-gapped tiers all support customer key custody
Access controlSSO (SAML 2.0 or OIDC), SCIM provisioning and RBAC at workspace, role and resource level
AuditKey lifecycle and access events exportable to SIEM (Splunk, Sentinel, QRadar, Datadog)
Sovereign custodyOn-prem HSM and air-gapped deployment supported for classified environments
AccountabilityDual control and quorum possible for revocation and rotation; events audit-ready

TL;DR

  • Your KMS or HSM holds the master key; revocation becomes a live control you operate.
  • Envelope encryption with AES-256 at rest and TLS 1.3 in transit keeps rotation cheap.
  • Keys can stay under national control in an on-prem HSM or KMS you operate.
  • Rehearse revocation with the same runbook you would use in an incident.
  • Start free with plugsky-micro and plugsky-lite; a 14-day full-access trial covers larger models.

How it works, step by step

  1. Decide which stores fall under customer-managed keys and name the owner of the key lifecycle.
  2. Create the key in your KMS or HSM and reference it from the Plugsky workspace.
  3. Rehearse rotation and revocation in staging before any production data is protected.
  4. Confirm the deployment tier and key custody model against the classification of the workload.
  5. Set dual control and quorum for revocation, rotation and break-glass access.
  6. Retain key lifecycle evidence to the records schedule and export it for review.
1Decide which storesfall undercustomer-managed2Create the key inyour KMS or HSM andreference it from3Rehearse rotationand revocation instaging before any4Confirm thedeployment tier andkey custody model5Set dual controland quorum forrevocation,6Retain keylifecycle evidenceto the records

Try it yourself

Open the AI API key security checklist →

BYOK for government teams: what changes

Government deployments rarely fail on model quality; they fail on custody, sovereignty and evidence. Classified or citizen-data workloads typically demand that keys live under national control, that personnel with access are accountable, and that the cryptographic boundary is documented for procurement review.

In practice, bring your own key (BYOK) creates a cryptographic boundary you operate: your KMS or HSM holds the master key, Plugsky uses it through envelope encryption to wrap per-object data keys, and revoking it stops access to everything protected by that key. AES-256 at rest with per-region KMS, TLS 1.3 in transit, and key permissions kept separate from platform administration are the baseline controls.

Architecture and controls

Hold master keys in an on-prem HSM or a KMS you operate, and choose air-gapped deployment where classification requires it. Enforce dual control with quorum for revocation and rotation, keep key lifecycle events audit-ready, and retain them to the schedule your records policy sets.

Integration pattern and rollout

Pilot in a controlled environment: pin the workload to an approved deployment tier, issue scoped keys per system, and rehearse revocation with the same runbook you would use in an incident. The OpenAI-compatible API carries the application layer over; the change is custody and deployment boundary.

The engineering work sits around the pipeline: reference the customer key from the workspace, keep the OpenAI-compatible call path unchanged, and automate rotation so it becomes routine rather than an incident. Export key lifecycle events to the same SIEM that receives authentication and admin events, and keep break-glass procedures in version control.

Limits, evidence and cost

BYOK does not itself confer accreditation. Compliance posture is readiness in progress for SOC 2 Type II and ISO 27001, and regulatory alignment depends on your jurisdiction — validate with counsel before committing classified workloads.

There is no separate line item for customer-managed keys on supported tiers; check the live pricing page for plan detail. The free plan covers plugsky-micro and plugsky-lite with no card, and the 14-day full-access trial lets you test the full capability set before you commit.

Honest comparison

ConcernPlugsky BYOKVendor-managed keysBuilding in-house
Key custodyYour KMS or HSM; keys separated from platform administrationVendor KMS and shared control planeYou build and run the whole stack
RevocationRevoke the key and protected access stopsUsually a vendor support processYou own the runbook
EvidenceKey lifecycle and access events exportable to SIEMVendor portal logsCustom logging pipeline
Operational loadYou own key availability, rotation and backupsVendor owns the lifecycleYou own everything
Time to controlConfiguration on supported tiersAvailable immediatelyQuarters of engineering
Sovereign custodyHSM and air-gapped key custody supportedRarely offeredYou build national-grade controls

Frequently asked questions

What does BYOK actually change?

You supply and control the master key through a KMS or HSM while Plugsky performs cryptographic operations with envelope encryption. Revoking your key stops access to protected data, and key operations stay auditable.

Who is responsible when a key is unavailable?

You are. Key availability becomes your availability, so plan KMS or HSM redundancy, break-glass procedures and incident response before go-live.

Does BYOK replace certification or a DPA?

No. It is one technical control. Compliance posture — SOC 2 Type II and ISO 27001 readiness in progress — and contractual terms such as the DPA must be reviewed separately.

Can keys stay under national control?

Yes. Master keys can be held in an on-prem HSM or a KMS you operate, and air-gapped deployment keeps the cryptographic boundary entirely inside your environment.

Who can revoke a key?

You decide. Enforce dual control with quorum for revocation and rotation, and separate those permissions from day-to-day platform administration.

Is BYOK enough for classified workloads?

It is one control. Combine it with air-gapped deployment, federated identity, audit export and personnel controls, and validate accreditation requirements with your own authority.