---
sourceDocument: Australia Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Cloud Encryption with Key Management

# Cloud Encryption with Key Management {#ariaid-title1}

* Release version: Australia
* 
* Updated May 21, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Cloud Encryption with Key Management

ServiceNow® Cloud Encryption provides encrypted database storage using block encryption, together with advanced key management capabilities.
Available as part of the Platform Encryption subscription bundle, Cloud Encryption enhances data security through segregation of duties, key rotation, and options for customer-managed keys.
This solution supports both production and non-production instances using MariaDB and RaptorDB databases, and is compatible with ServiceNow Commercial Cloud, Government Customer Cloud (GCC) pod 101, and ServiceNow Protected Platform -- Australia (SPP-AU).
Show full answer Show less  

## Key Features

* **Key Management Operations:** Enables customers to access and manage encryption keys, perform key rotations, and withdraw customer-managed keys as needed.
* **Customer-Managed Keys and BYOK:** Customers can bring their own key material, rotate keys, and withdraw keys while ServiceNow holds the key on its infrastructure. This allows control without hosting keys on customer infrastructure.
* **Quorum Control Policy:** When key withdrawal is activated (via an optional add-on SKU), customers can set policies defining the minimum approval count required for key withdrawal, enhancing governance and security.
* **Key Management Transactions:** Provides a complete audit trail of all key-related transactions within the ServiceNow instance for transparency and compliance.
* **Tamper Detection:** Detects unauthorized changes to quorum control settings to improve overall security posture.
* **Cloud Encryption UI:** Accessible by security administrators with the appropriate role, allowing visibility into active keys and encryption status of the instance.

## Licensing and Activation

Cloud Encryption requires the Platform Encryption subscription bundle. New ServiceNow instances for licensed customers come with Cloud Encryption provisioned. Existing instances must be moved to Cloud Encryption via a formal request process, requiring customer or partner admin roles. Enabling Cloud Encryption necessitates a one-hour maintenance window.

## Practical Benefits for ServiceNow Customers

* Enhanced data security through strong encryption and robust key management.
* Control over encryption keys with options to bring your own keys, rotate, or withdraw keys without needing to manage infrastructure.
* Improved compliance and auditability via transaction logging and tamper detection.
* Governance over key withdrawal through configurable quorum policies ensures secure and authorized key management actions.  
ServiceNow®
Cloud Encryption offers encrypted storage for the database using block
encryption, along with enhanced key management. Cloud Encryption is available
with the ServiceNow® Platform Encryption subscription bundle.  
Cloud Encryption offers:

* Segregation of duties.
* Rotation of ServiceNow Managed keys.
* Customer-Managed keys option.  
  Note:  
  With customer-managed keys, ServiceNow holds the encryption key on its infrastructure, but you perform key operations on it. Managing your key means you can bring your own key material (BYOK), rotate ServiceNow-managed or customer-managed keys, and withdraw your key. Keys aren't hosted on your own infrastructure. See [Key management operations](https://www.servicenow.com/docs/cy6Bd4q8v7FPypxhDGvPpg#key-mgmt-operations-ce "The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.") for details.
{#dare-overview__ul_jhg_jjq_frb}

The following diagram shows how Cloud Encryption works.  
The Cloud Encryption Key Management module consists of the following submodules:

* [Key management operations](https://www.servicenow.com/docs/cy6Bd4q8v7FPypxhDGvPpg#key-mgmt-operations-ce "The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption."):
  * Access the list of keys.
  * Perform key rotation operations.
  * Withdraw customer-managed key.
  {#dare-overview__ul_amd_gxq_frb}
* [Key management transactions](https://www.servicenow.com/docs/jzjRM6n0Olpdts7I~SZmAQ "The Key Management Transactions submodule displays all transactions that have occurred for the keys in your ServiceNow instance."):

  Reference all transactions that have occurred for the keys that have been used. Bring your own encryption key (BYOK) for use with Cloud Encryption.

  Use your own customer-managed key for encryption.
{#dare-overview__ul_dbr_tjq_frb}

In certain circumstances, you may opt for a key withdrawal request when using a customer-managed key. To do so, you must license the Cloud Encryption Withdraw and Resupply optional add-on SKU and then request the key withdrawal
functionality be activated by a Customer Service and Support team member.

The Quorum Control Policy Settings option becomes available when the withdrawal feature is activated, otherwise the module isn't visible on the menu. This feature can be activated only when using customer-managed keys. This policy
enables settings to be configured regarding quorum when the withdrawal feature is activated. For more details on this feature, see [Quorum Control Policy](https://www.servicenow.com/docs/1FhOSqBbY1ji_JNBZHY99A "The Quorum Control Policy specifies the minimum number of approvals required among the total number of selected approvers to reach quorum for customer managed key withdrawal.").

Cloud Encryption supports production and non-production instances for MariaDB and RaptorDB databases. Cloud Encryption is supported in the ServiceNow Commercial Cloud, Government Customer Cloud (GCC) pod 101, and ServiceNow Protected Platform -- Australia (SPP-AU).

## Licensing and enabling Cloud Encryption {#dare-overview__section_hb4_dsl_kcc}

For information about licensing Cloud Encryption, see [Encryption and Key Management subscription bundle](https://www.servicenow.com/docs/tvHtz~M_HJ8xon3itLmsLw "With Key Management, Field Encryption is upgraded at no additional charge to include highly configurable encryption modules. You can also optionally upgrade to the unlimited-use license. Subscribe to the new encryption entitlement bundle, Platform Encryption, which includes Field Encryption Enterprise and Cloud Encryption.").

For licensed customers with new instances, the new instance provisioning will include Cloud Encryption.

For licensed customers with existing instances, to request an instance be moved to Cloud Encryption, follow the instructions in [KB1117369](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1117369). You must have the customer admin or partner admin role to request the Service Catalog item to Enable Cloud Encryption on your instance. Enabling this feature requires a one-hour maintenance
window.

## Cloud Encryption UI {#dare-overview__section_n31_sm2_w1c}

When Cloud Encryption is enabled, the Cloud Encryption user interface (UI) is visible to the security_admin user when this user has the sn_kmf.admin role.

To access the Cloud Encryption UI by searching for Cloud Encryption Key Management in the navigation bar. Navigate to the Key Management Operations section to see information about
encryption keys, such as details of the active key, and whether Cloud Encryption is enabled for the instance.
* **[Key management operations](https://www.servicenow.com/docs/cy6Bd4q8v7FPypxhDGvPpg#key-mgmt-operations-ce)**   
  The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
* **[Quorum Control Policy](https://www.servicenow.com/docs/1FhOSqBbY1ji_JNBZHY99A)**   
  The Quorum Control Policy specifies the minimum number of approvals required among the total number of selected approvers to reach quorum for customer managed key withdrawal.
* **[Key management transactions](https://www.servicenow.com/docs/jzjRM6n0Olpdts7I~SZmAQ)**   
  The Key Management Transactions submodule displays all transactions that have occurred for the keys in your ServiceNow instance.
* **[Cloud Encryption logging](https://www.servicenow.com/docs/J1BsJPOecMNWWW0xya6snw)**   
  Learn about logging options for Cloud Encryption.
* **[Tamper Detection](https://www.servicenow.com/docs/ezKTetPKfBEOnGNUCMmT0w)**   
  Use tamper detection to improve security by detecting unauthorized changes to your quorum control settings.

