Set up BYOK encryption

Enrollment in BYOK encryption is no longer available. You can opt to enroll in Customer-managed keys (CMK) encryption, which offers enhanced control over encryption keys for safeguarding your Atlassian Cloud data. Existing BYOK customers will eventually be migrated to CMK.

Who can do this?
Role: Organization admin
Atlassian Cloud: Jira, Confluence, and Jira Service Management customers with Enterprise plan
Atlassian Government Cloud: Not available

Adding a BYOK-encrypted Atlassian app

Before you can set up CMK-enabled Atlassian apps, you need to:

  • Set up your AWS account

  • Create the IAM role

If you don’t already have these set up, you will instead need to enroll in Customer managed keys (CMK) encryption. See What is CMK encryption?

Currently, we don’t support migration of data between locations.

You can’t convert a BYOK-encrypted app into a non-BYOK app (an app with data encrypted with Atlassian-managed keys).

When you add an Atlassian app, you have the choice of using an Atlassian managed key or BYOK, giving you greater control over encryption keys.

To set up a BYOK-enabled Atlassian app:

  1. Go to Atlassian Administration. Select your organization if you have more than one.

  2. Select Apps, then Atlassian apps

  3. Select Add app to display the Atlassian app available.

  4. From the list, find the Atlassian Enterprise app you wish to add, and select Add app.

  5. Select whether you’d like to use a new or an existing site, then enter (or select) its URL.

  6. Select Next.

  7. From the Encryption dropdown, select Bring your own key (BYOK) encryption.

  8. Select Add.

Provisioning of your Atlassian app will now begin. Learn what data is managed with BYOK encryption

View your BYOK-encrypted apps

To view your BYOK-encrypted apps:

  1. Go to Atlassian Administration. Select your organization if you have more than one.

  2. Select Security, then Data protection, then Encryption.

 

Still need help?

The Atlassian Community is here for you.