Overview
Oracle Databases and adopt Oracle Cloud Infrastructure (OCI) power the world's most mission-critical workloads, from core banking to healthcare records. Stringent data privacy regulations, rising breach risk, along with security best practices call for encryption keys to be stored separately from the data they protect, with full lifecycle management, fine-grained access policies, and comprehensive audit trails across hybrid and multicloud infrastructure.
For organizations operating under strict data sovereignty requirements, the need goes further: the ability to manage and keep encryption keys outside of Oracle’s control is not optional.

Fortanix Solution
Fortanix Data Security Manager (DSM), a next-generation Hardware Security Module with built-in Key Management, secures data at rest, in transit, and in use, while giving enterprises sovereign control over their keys everywhere Oracle runs.
DSM extends Oracle Transparent Data Encryption (TDE), encrypting data with no changes to schemas, applications, or workflows. Keys are stored separately from the data they protect, meeting GDPR, PCI DSS, and other regulatory requirements by design. For Oracle Cloud Infrastructure, Fortanix DSM natively integrates with OCI Vault, giving enterprises Bring Your Own Key (BYOK) and Hold Your Own Key (HYOK) in FIPS 140 Level 3 HSM, with full control over keys stored entirely outside OCI infrastructure.
DSM’s software-defined architecture enables enterprises to seamlessly migrate to the latest NIST-recommended Post-Quantum Cryptography (PQC), with no re-architecture required.

Benefits
Unified Platform for All Your Keys
Manage encryption keys across OCI and on-premises infrastructure from a single console. Rapidly migrate to latest PQC algorithms.
Centralized Compliance Control
Apply granular access controls and quorum approval workflows across all key operations, backed by centralized audit logs.
Sovereign Cloud Readiness
Enforce data residency and access policies with cryptographic assurance, ensuring neither Oracle nor any third party can access protected data.
Resources

Solution Brief
Using Fortanix Data Security Manager with Oracle Transparent Data Encryption (TDE)




