Skip to content
deny.sh
Connections BYOK
Documentation ↗

DENY.SH CONSOLE

Your workspace starts here.

Sign in to manage your account.

Connections

BYOK, AWS KMS

View your AWS KMS connection and configuration.

About BYOK

Bring your own AWS KMS key. Every server-stored managed vault ciphertext is wrapped with a per-record AES-256-GCM DEK that is encrypted under your CMK. Platform teams keep the root key in AWS and can revoke deny.sh access through IAM.

Loading…