Key Management Service (KMS)
A managed key service is planned for Origin Cloud — centralized key storage with an encrypt/decrypt API. This page describes what we intend to build.
Features
Secure Key Storage
Keys are created and stored inside the service, versioned, and rotatable.
Encryption and Decryption
Encrypt and decrypt payloads through the API without the key material leaving the service.
Designed for Compliance Programmes
Designed to support centralized key management for GDPR and PCI-DSS programmes — not yet available for compliance workloads.
Use Cases
Application Data Encryption
Envelope-encrypt records in your own database with a data key you never store yourself.
Secure Backups
Encrypt database dumps and volume snapshots so a leaked backup is not a leaked dataset.
Regulatory Requirements
Intended for teams that must manage encryption keys under financial or legal regulations.
Planned Service
Note: KMS is not yet built. This page describes the service we intend to offer, and its priority follows customer feedback.
Register to get started with what's live today, or check our Launch Strategy for this service's timeline.
New organisations are reviewed before the first launch — open beta runs on limited capacity, so we check we can host you, usually within a few hours.