Skip to main content Skip to navigation Skip to footer

Own the keys. Own the encryption. No exceptions.

Every backup is encrypted with locally owned keys. Not the vendor's keys. Not shared keys. One owner only.

THE PROBLEM

Vendor-managed keys belong to the vendor

Here's the part nobody says out loud. Most backup tools encrypt data with their keys, not the customer's. So they can open it. Their staff can open it. If they get hacked, the data is wide open. Whoever controls the keys controls the data.

Only 8% of companies encrypt 80%+ of their cloud data 1 Thales 2025 Cloud Security Study
$4.88M average cost of a data breach globally 2 IBM Cost of a Data Breach Report 2024
57% of companies juggle 5+ key systems, leaving blind spots 1 Thales 2025 Cloud Security Study
THE REAL COST

What does weak encryption governance cost?

Drag the sliders to match the environment. See the real cost of vendor-managed encryption.

HOW IT WORKS

One command. Total control.

1

Generate

Run rdc keygen production. This makes a 4096-bit key pair that never leaves the machine. No one else gets a copy.

2

Encrypt

Every backup gets locked with AES-256-GCM using that key. Data stays encrypted on disk and on the move. It happens automatically.

3

Control

We never see the key. We never see the raw data. Only the key holder can unlock it. That's what zero-knowledge means: we hold nothing.

Backup Data Plaintext
gitlab 42 GB
nextcloud 128 GB
mailcow 84 GB
mariadb 96 GB
Encrypt
AES-256-GCM
Encrypted Backup Sealed
gitlab AES-256
nextcloud AES-256
mailcow AES-256
mariadb AES-256
UNDER THE HOOD

Why vendor-managed encryption fails

When the vendor holds the keys, they can open the data. Their staff can too. One breach on their side and everything spills out. We do it the opposite way. The keys stay with the customer. We never see raw data or keys. Honestly, that's how it should have always worked.

Short on time?

Skip the deep-dive. Grab the five-minute version, short enough to read at a stand-up.

Download short brief (PDF)
THE GAP

Encryption control compared

Most backup tools encrypt data with their keys. That's not customer encryption. That's vendor encryption.

Sources(21)
  1. Thales, "2025 Cloud Security Study," conducted by S&P Global 451 Research, 2025. "Only 8% of organizations encrypt 80% or more of their cloud data." "57% use five or more encryption key managers."
  2. IBM Security, "Cost of a Data Breach Report 2024," July 2024. "The global average cost of a data breach reached $4.88 million in 2024."
  3. Veeam supports external KMS integration for encryption key management including AWS KMS and Azure Key Vault.
  4. Rubrik supports customer-managed encryption keys via external KMS integration including KMIP-compatible servers.
  5. Commvault integrates with AWS KMS, Azure Key Vault, HashiCorp Vault, and KMIP-compatible key management servers.
  6. Druva Enterprise Key Management (BYOK) lets customers use their own AWS KMS keys to encrypt backup data.
  7. Veeam supports encryption key rotation through KMS integration for compliance with security policies.
  8. Rubrik supports encryption key rotation through its KMS integration for enterprise key management.
  9. Commvault supports automated encryption key rotation via the Rotate Encryption Master Keys workflow with configurable intervals.
  10. Druva supports both cloud encryption key and customer-managed AWS KMS key rotation for security compliance.
  11. Veeam encrypts backup data at rest using AES-256 encryption with hardware acceleration support.
  12. Rubrik encrypts all data at rest using AES-256 encryption with software or hardware-based key management.
  13. Commvault supports AES-256 encryption at rest with hardware-accelerated AES-NI support for backup data.
  14. Druva encrypts all data at rest with AES-256 using unique per-customer Data Encryption Keys.
  15. Veeam encrypts all data in transit using TLS for network traffic between backup components.
  16. Rubrik encrypts all data in transit using TLS 1.2+ between cluster nodes and remote targets.
  17. Commvault encrypts network traffic in transit using mutual TLS 1.3 with AES_256_GCM_SHA384 cipher suite.
  18. Druva encrypts all data in transit with TLS 1.2 (256-bit) between customer environment and Druva Cloud.
  19. Veeam Backup & Replication is deployed on-premises on Windows Server with full customer control over infrastructure.
  20. Rubrik is deployed as on-premises appliances (r6000 series) with integrated compute, storage, and software.
  21. Commvault supports fully self-hosted on-premises deployments with CommServe, MediaAgent, and Access Node components.

Own the encryption keys

Generate the first key in under a minute. Start the 14-day free trial.

Start free trial
$ rdc repo up production