Every secret is encrypted before it is stored. Each value gets its own data key, and that data key is wrapped by the encryption key of its vault. The encryption keys never leave the key management service that holds them: FerrVault asks it to wrap and unwrap, nothing more.

The Keys page, under Organization in the app, lists the keys your vaults can use and the vaults using each one.

Getting a key

New key offers two ways.

Generate a key. FerrVault creates the key and manages it for you. Pick where it lives:

  • OVHcloud KMS, with Software or HSM protection. An HSM key never exists outside dedicated hardware. Your plan includes a number of HSM keys; past that, pick Software.
  • FerrVault, where the key is held by FerrVault's own key service, software-protected under a root key FerrVault holds in its own KMS. Offered when the deployment runs that service.

Generated keys count against your plan's managed-key quota. Generating a key, like destroying a generated one, takes an owner or admin of the organization: both change what the organization is billed.

Use an existing key. Paste the identifier of a key you already have, in OVHcloud KMS, AWS KMS or a Vault Transit engine this deployment can reach. FerrVault wraps and unwraps a test value with it before saving it, so a key it cannot use is refused there rather than when your first secret is written.

Choosing a vault's key

A vault's key is picked when the vault is created, and can be changed from its settings at any time. Switching re-encrypts every data key of the vault under the new key, in the background, and secrets stay readable throughout.

Several vaults can share one key, which is how you group vaults by domain on a handful of keys. Vaults sharing a key rotate together, and deactivating that key stops all of them.

Rotating a key

Rotate in place, in a vault's settings, moves the vault onto a new version of the same key and re-encrypts its data keys under it:

  • a FerrVault key gets a new version on the spot;
  • a Vault Transit key must be rotated in Transit first;
  • an OVHcloud KMS key has no versions, so rotating means switching the vault to a new key.

Deleting a key

A key can be deleted once no vault uses it and no rotation away from it is still running.

  • A generated key is destroyed: FerrVault deactivates it at once and deletes it from its key service 60 days later. Until then it still counts against your quota, since it is still billed. It cannot be used again, and generating a new key under the same name waits until the old one is gone.
  • A key you added is only removed from the list. It stays where it lives, and so does whatever it costs there.

A generated key that no vault uses is flagged on the Keys page, since it is still billed.

When a subscription ends

Generated keys stay active for 30 days after a subscription ends. They are then deactivated, which makes their vaults unreadable without deleting anything, and deleted 60 days later. Renewing before that brings them back. Keys you added are never touched.