Bring Your Own Key (BYOK) Encryption is an encryption feature that allows you to supply and use your own encryption key to enhance the security of your data in Jamf Cloud. When using BYOK, you have additional control over some encrypted data and the ability to revoke access to the key, which would in effect revoke access to the data. You store your encryption key in a supported key management system (KMS), and Jamf uses access to that key to secure your data.
This is sometimes referred to as Hold Your Own Key (HYOK) or Customer Managed Keys (CMK). At Jamf, we use the term BYOK.
Data is encrypted and decrypted at the application layer, so that Jamf applications can view and operate on your data. However, Jamf cannot read your data in its unencrypted state. You can revoke access to your data, including data in backup copies, at any time by withholding access to your key. Optionally, you can log key access for auditing purposes.
BYOK allows you to do the following:
-
Maintain control over your encryption keys and your data. For more information about the specific encryption keys and data that is encrypted in Jamf Pro, see Database Encryption in the Jamf Pro Security Overview.
-
Change and rotate your key according to your security policies. Automatic key rotation configured within your KMS is supported
-
Revoke access to your encryption key to limit exposure in the event of a data breach, without Jamf intervention required
-
Meet stringent security and compliance requirements for cloud storage