Solution brief

Fortanix Key Management

Get complete control and visibility into cloud encryption keys

Download Solution Brief

Request a Demo

hero section

Problem

The volume of data stored on the public cloud is growing exponentially. With this growth, the challenges of data security, regulatory compliance and the risk of data breaches grow. Cloud-native encryption relies on the cloud platform provider to secure data. Under this approach, cloud providers generate and own the data encryption keys directly to encrypt the data-at rest in cloud. With this approach, customers do not get control over the cloud keys.

Solution Overview

Unlike cloud native solutions, Fortanix allows businesses to retain control and management of encryption keys with centralized management, consistent access control policy and centralized audit logs. Fortanix also offers Bring your own key management service (BYOKMS) allowing customers to store cloud keys externally within own datacenters thereby help meet the most stringent compliance requirements. Flexible deployment options with Software, SaaS and FIPS 140-2 level 3 HSM appliance.

diagram 1

Solution Benefits

Centrally Manage Your Encryption Keys
Centrally Manage Your Encryption Keys

Fortanix Data Security Manager provides control of and visibility into your key management operations using a cen- tralized web-based UI with enterprise level access controls and single sign-on support. Securely generate, store, and use crypto keys, certificates, secrets, passwords, API Keys, tokens etc.

Single Solution for Multi-Cloud
Single Solution for Multi-Cloud

Fortanix Data Security Manager enables you to make a secure transition to multi cloud. With HSM grade security, FIPS 140-2 level 3 protection for all keys, organizations can adopt BYOK, meet cloud security, compliance requirements and resist cloud provider lock-in.

External Key Manager
External Key Manager

Fortanix has partnered with GCP to create Google Cloud External Key Manager (EKM), to enable customers to bring their own key management system and manage keys externally on customers datacenters.

DevOps and Cloud Friendly APIs
DevOps and Cloud Friendly APIs

Fortanix Data Security Manager supports extensive RESTful APIs, PKCS#11, KMIP, JCE, Microsoft CAPI, and Microsoft CNG. Easily support all existing and new applications, whether operating in public, private, or hybrid cloud.

Solution Highlights

Simplified KMS Policy Management
Simplified KMS Policy Management

Apply consistent key management policies across multiple cloud providers, tenants and regions.

Cloud Encryption Key Disaster Recovery
Cloud Encryption Key Disaster Recovery

Back up, restore, and re-import master encryption keys for public cloud KMS.

External Key Management
External Key Management

Key Manager extends existing cloud-native KMS to separate encryption keys from the data being secured.

FIPS 140-2 Level 3 Compliant
FIPS 140-2 Level 3 Compliant

The solution can also be deployed as a FIPS 140-2 Level 3 HSM.

Flexible Deployment Options
Flexible Deployment Options

Solution is available as a software, SaaS, and hardware appliance.

Consolidated Audit Logging
Consolidated Audit Logging

Secure, comprehensive audit logs to help meet compliance.

Quote
When you move to the cloud, you lose that control... So the Fortanix solution brings an ability to control the keys externally. You can turn the keys off, turn them on– they are totally under your control. The other advantage is with PayPal’s requirements is it actually enables new business use cases to go to the cloud.

Paypal

How it Works

Control Keys to the Cloud
Control Keys to the Cloud

Fortanix delivers full key lifecycle management as a service to ensure secure and consistent key management across multi cloud environments, including bring your own key (BYOK) and bring your own key management service (BYOKMS). Fortanix lets organizations pick the right level of control depending upon business use case and required security posture.

Bring Your Own Key (BYOK)
Bring Your Own Key (BYOK)
  • Upload master keys
  • API to manage keys
  • Cloud-based access control
Bring Your Own KMS (BYOKMS)
Bring Your Own KMS (BYOKMS)
  • Maintain control of keys
  • API to encrypt/decrypt
  • Granular RBAC and logging

Diagram 2

See how Fortanix strengthens and accelerates your enterprise compliance workflows in a personalized demo.
Fortanix-logo

4.6

star-ratingsgartner-logo

As of August 2025

SOC-2 Type-2ISO 27001FIPSGartner LogoPCI DSS Compliant

US

Europe

India

Singapore

3910 Freedom Circle, Suite 104,
Santa Clara CA 95054

+1 408-214 - 4760|info@fortanix.com

High Tech Campus 5,
5656 AE Eindhoven, The Netherlands

+31850608282

UrbanVault 460,First Floor,C S TOWERS,17th Cross Rd, 4th Sector,HSR Layout, Bengaluru,Karnataka 560102

+91 080-41749241

T30 Cecil St. #19-08 Prudential Tower,Singapore 049712