How it plays out on a deal
With customer-managed keys, the client can cut off the provider's ability to decrypt its data by revoking the key. Banks, defense suppliers and some life sciences companies ask for it to meet internal policies on third-party access.
It adds operational weight. If the client loses or revokes the key by mistake, the room becomes unreadable. It is usually limited to enterprise tiers and quoted separately, so it is worth confirming early whether a requirement truly exists before paying for it.
What to check in a review or demo
- 1Whether the option exists and on which plans.
- 2Which key services are supported and who handles rotation.
- 3What happens to the room and its archive if the key is revoked.
Read alongside
- Encryption at restScrambling stored files, backups included, so that anyone who walks off with a disk or a backup set gets unreadable data unless they also hold the keys.
- AES-256The Advanced Encryption Standard with a 256-bit key, a widely used symmetric cipher that most data rooms cite for encrypting stored files.
- Data residencyWhich jurisdiction physically hosts a room's files, and whether the customer can pick it, for instance an EU, UK, US or Australian region chosen when the room is created.
- Quote-based pricingPricing that is not published and is set per project after a scoping call, usually bundling size, users, term, features and service level into one figure.