DuoKey

Salesforce Encryption

Keep Salesforce from unlocking your pipeline alone

Customer and opportunity data stay useful in Salesforce, without giving the CRM the last encryption key.

The problem

Salesforce keys still live too close to the CRM

Platform encryption without independent custody leaves customer records exposed.

CRM data is a high-value target. If encryption keys sit in the same operational plane as Salesforce, a platform incident, insider, or compelled request can still reach the records.

  • Keys in the CRM plane

    Salesforce operations stay on the path to unwrap.

  • GDPR / HIPAA / CCPA

    Those regimes assume exclusive control of the key.

  • CacheOnly exposure

    Unwrapped keys in memory widen who can read records.

  • BYOK in name only

    If the platform can still use the key, custody is shared.

Security leadership

What the board is asking

Salesforce Encryption

Four questions surface in every security review.

Talk to our security architects

What changes

Customer-held keys for Salesforce CRM data

DuoKey for Salesforce provides software-based key service integration for External Key Management (EKM), BYOK and Cache-Only Key using secure Multi-Party Computation (MPC), enabling full control over encryption keys stored outside Salesforce while ensuring data sovereignty and compliance with FINMA, HIPAA, GDPR regulations.

  • Ensure GDPR compliance and protect personally identifiable information (PII) and sensitive data

  • Easily integrate our solution into your existing Salesforce environment

  • Bring Your Own Key and securely manage encryption keys within your organization.

  • Encrypt and decrypt data on the customer side, minimising exposure of sensitive information

In detail

What changes for revenue and risk teams

External Key Management (EKM)

Salesforce provides Bring Your Own Key (BYOK) and External Key Management (EKM) features that allow customers to use their own encryption keys for securing their data stored in Salesforce. EKM enables organisations to store and manage encryption keys outside of Salesforce's infrastructure, providing an additional layer of control and security.

Products

Related products

Microsoft Double Key Encryption (DKE)

Keep Microsoft from unlocking regulated mail, files and Teams content alone, without leaving M365.

View product

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.