Skip to content
Clumio

Enhancing Clumio’s Bring Your Own Key (BYOK) Feature

Don’t you love the beginning of the year when you come up with a resolution that gives a surge of motivation to achieve? But as new priorities emerge, your determined sprint inevitably becomes a leisurely walk. So long as you periodically remind yourself why you made the resolution in the first place, even slow progress will eventually get you to your goal.


That sense of accomplishment accompanies an added sense of relief, regardless of how long it took to achieve. But…what does this have to do with Bring Your Own Key (BYOK)? Read on.

Along similar lines, Clumio’s Backup as a Service Cloud promised to support the BYOK feature more than 2 years ago! This feature allowed customers to encrypt their backup data using their own encryption key using the Amazon Web Service (AWS) native Key Management Service (KMS) feature.

O AWS KMS facilita aos clientes a criação e o gerenciamento de chaves criptográficas, além de permitir o controle de seu uso em uma ampla gama de serviços da AWS e em seus aplicativos.

When Clumio added the BYOK feature, it supported VMWare, Microsoft 365 (M365) and AWS EC2/EBS data sources as these were the data sources Clumio supported at that time. However, between then and now, Clumio added additional critical data sources like S3, RDS and DynamoDB.

Now with the most recent release, Clumio has brought BYOK capabilities to all of our critical data sources, and in doing so has achieved the resolution we started long ago. And it doesn’t stop here, as we will continue to invest efforts to bring BYOK to future data sources also.

Por que os clientes se interessam pelo BYOK:

Doesn’t Clumio encrypt all backups already, and if yes, why is BYOK needed? It’s true that Clumio does encrypt all the backup data in its cloud with a customer-dedicated key, and that key is also rotated every 30 days. However, in some cases, certain customers have additional stringent security requirements:

Como funciona a criptografia:

As chaves de bucket do AWS S3 reduziram o custo da criptografia no lado do servidor em mais de 99% and don’t need to lookup the key for every single transaction. Since Clumio backs up data with millions of transactions, having to look up the key for every single transaction was a no-go. With AWS’S S3 bucket keys feature, Clumio can use the customers BYOK key as the Amazon S3 Bucket Key and encrypts all the data landing in the S3 bucket using the customers BYOK key.

Como ativar o recurso BYOK:

Go to Settings and Security Features – Encryption Key. When you go to the page, Clumio provides details about the feature, along with its requirements and limitations. Customers can proceed by deploying the AWS CloudFormation StackSets inside any one of their AWS accounts where they want to use the BYOK key.

O motivo pelo qual o StackSets é necessário é que o Clumio precisará criar uma chave multirregional (global) e utilizá-la para criptografar backups em todas as regiões onde as fontes de dados estiverem presentes. Após a implantação bem-sucedida, os clientes podem verificar a conexão na interface do usuário do Clumio acessando a página a qualquer momento.

A marca de seleção verde na parte superior da página indica que tudo está funcionando conforme o esperado. Se, por qualquer motivo, a chave não estiver acessível, ela se transforma em um X vermelho e permite que você verifique o acesso novamente para ver se o problema foi resolvido e se tudo está funcionando normalmente.

Screenshot of Clumio Encryption Key - Check Access

How to verify and audit Clumio’s Access

Uma das vantagens do recurso BYOK é que os clientes podem verificar e auditar a qualquer momento quando a Clumio acessou sua chave. Os clientes podem acessar os registros do CloudTrail e ver todos os detalhes de cada vez que a Clumio acessa sua chave, incluindo o motivo do acesso. Os clientes podem acessar a seção “Registros do CloudTrail” em sua conta da AWS, onde o AWS CloudFormation StackSet foi implantado.

No caso das chaves de buckets do S3, como elas são armazenadas em cache pelo próprio S3 da AWS, o acesso a elas pode não ocorrer em todas as transações. No entanto, as chaves são acessadas em todas as transações para backups de EC2/EBS, VMware e M365.

Screenshot of the CloudTrail logs

O que acontece quando a chave não está mais acessível:


Remember this: BYOK gives you the power of encrypting all backup data, but on the flip side, if the key is lost, then you’re in big trouble! Luckily, keys in AWS aren’t like physical keys and even if someone deletes them, os clientes ainda têm 30 dias para recuperá-las. Se, por qualquer motivo, as chaves não forem recuperadas, os dados de backup ficarão inutilizáveis. Esse recurso foi concebido para servir como um mecanismo de segurança contra falhas, mas é preciso ter muito cuidado ao utilizá-lo.

More related posts


Thumbnail_Blog-Tabletop-Exercise-2026

SaaS Matters – Enterprise Support Made Possible by Clumio

Read more about SaaS Matters – Enterprise Support Made Possible by Clumio
Thumbnail_Blog-QTFY-Advisory-2026

The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.

Read more about The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.
Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio