Skip to main content
Planned

Key Management Service (KMS)

A managed key service is planned for Origin Cloud — centralized key storage with an encrypt/decrypt API. This page describes what we intend to build.

Features

Secure Key Storage

Keys are created and stored inside the service, versioned, and rotatable.

Encryption and Decryption

Encrypt and decrypt payloads through the API without the key material leaving the service.

Designed for Compliance Programmes

Designed to support centralized key management for GDPR and PCI-DSS programmes — not yet available for compliance workloads.

Use Cases

Application Data Encryption

Envelope-encrypt records in your own database with a data key you never store yourself.

Secure Backups

Encrypt database dumps and volume snapshots so a leaked backup is not a leaked dataset.

Regulatory Requirements

Intended for teams that must manage encryption keys under financial or legal regulations.