security · 1 min read
Customer-Managed Keys: BYOK and HYOK Patterns
BYOK lets customers control encryption keys; HYOK lets them control them on their own HSM. Here is when each pattern matters and how Bhogar AI supports both.
BABhogar AI TeamProduct & Engineering
For some customers, "you handle our encryption keys" is a deal-breaker. BYOK and HYOK patterns let them keep control while still using a hosted platform.
Why it matters
BYOK uses cloud KMS the customer controls; HYOK uses customer-owned HSMs. Each adds operational complexity but unlocks specific compliance and contractual obligations.
How Bhogar AI approaches it
Bhogar AI supports BYOK with customer-managed AWS KMS / Azure Key Vault / GCP KMS keys, and HYOK with FIPS-140-3 HSMs via PKCS#11. Key revocation immediately renders ciphertext unreadable.
- BYOK across AWS KMS, Azure Key Vault, GCP KMS
- HYOK via PKCS#11 to FIPS 140-3 HSMs
- Immediate revocation
- Per-tenant key isolation
- Audit log of every key use
What you get
Customers in jurisdictions with strong sovereignty rules ship Bhogar AI without compromising their key custody requirements.