Skip to content

security · 1 min read

Customer-Managed Keys: BYOK and HYOK Patterns

BYOK lets customers control encryption keys; HYOK lets them control them on their own HSM. Here is when each pattern matters and how Bhogar AI supports both.

BABhogar AI TeamProduct & Engineering

For some customers, "you handle our encryption keys" is a deal-breaker. BYOK and HYOK patterns let them keep control while still using a hosted platform.

Why it matters

BYOK uses cloud KMS the customer controls; HYOK uses customer-owned HSMs. Each adds operational complexity but unlocks specific compliance and contractual obligations.

How Bhogar AI approaches it

Bhogar AI supports BYOK with customer-managed AWS KMS / Azure Key Vault / GCP KMS keys, and HYOK with FIPS-140-3 HSMs via PKCS#11. Key revocation immediately renders ciphertext unreadable.

  • BYOK across AWS KMS, Azure Key Vault, GCP KMS
  • HYOK via PKCS#11 to FIPS 140-3 HSMs
  • Immediate revocation
  • Per-tenant key isolation
  • Audit log of every key use

What you get

Customers in jurisdictions with strong sovereignty rules ship Bhogar AI without compromising their key custody requirements.

See Bhogar on your own data

Book a 45-minute working session. We connect one of your sources, build one agent, run one governed workflow, and review the trace together.