Key management
EVERTRUST Stream supports integrating with third-party KMSs and HSMs to secure signing private keys.
Integrating with a KMS
The recommended way to set up a KMS-protected key in Stream is to use the native Cloud KMS integration.
It’s also recommended that customers uses their cloud provider tenant to provision KMS keys, as this allows for reversibility and credentials management that is compliant with their own internal policies. In case the customer is unable to configure a KMS key in their tenant, EVERTRUST can provide a ready-to-use key. However, this has the same drawbacks as an EVERTRUST-managed customer bucket.