OpenKCM

OpenKCM is an open source central key chain manager for customer-owned encryption keys. It gives organizations full governance over their key hierarchy — from root keys down to data encryption keys — across cloud-native and on-premise deployments. Customers retain exclusive control over their key material, with immediate revocation across all governed workloads.
  • Customer-Owned Key Governance: Puts the customer in control of the full key hierarchy — from root keys to data encryption keys — without handing key material to any platform or vendor.
  • Unified Keystore Control Plane: Manages encryption keys across several platforms and heterogeneous infrastructure providers from a single control layer.
  • BYOK & HYOK Support: Supports Bring-Your-Own-Key and Hold-Your-Own-Key scenarios so customers retain full control over their cryptographic keys and can revoke access at any time.
  • Keychain Composition & Lifecycle Control: Composes data encryption keys into keychains and controls the key lifecycle of different keychains individually.
  • Pluggable Keystore Backends: Connects to OpenBao, AWS KMS, Azure Key Vault, GCP KMS, and HSMs — key material never leaves the customer's own keystore.
  • Compliance Ready: Ensures compliance with stringent security and privacy standards across multi-tenant cloud-native and enterprise platforms.

 

 

Access the full CISERO experience and discover all available resources.

 

Access the Platform

Already have an account? Login