
問題点
ベンダー管理の鍵は本当にあなたのものではない
ほとんどのバックアップツールはデータを暗号化します — 彼らの鍵で。つまり彼らがアクセスできます。彼らの従業員がアクセスできます。彼ら側の侵害であなたのデータが露出します。鍵を管理していなければ、データを管理していません。
実際のコスト
弱い暗号化ガバナンスにどれだけのコストがかかりますか?
スライダーを環境に合わせてドラッグしてください。ベンダー管理暗号化の実際のコストをご覧ください。
仕組み
1コマンド。完全な制御。
1
生成
rdc keygen productionを実行。あなただけが持つ4096ビットRSA鍵ペアを作成。
2
暗号化
すべてのバックアップがあなたの鍵でAES-256-GCMシール。データは保存時も転送時も自動的に暗号化。
3
管理
ゼロ知識アーキテクチャ。Rediaccはあなたの鍵を見ることも、平文に触れることもありません。復号できるのはあなただけ。
バックアップデータ 平文
gitlab 42 GB
nextcloud 128 GB
mailcow 84 GB
mariadb 96 GB
暗号化
AES-256-GCM
暗号化バックアップ 封印済み
gitlab AES-256
nextcloud AES-256
mailcow AES-256
mariadb AES-256
技術詳細
ベンダー管理暗号化が失敗する理由
ベンダー管理暗号化とは、ベンダーが鍵を保持することです。彼らがデータを復号できます。彼らの従業員がアクセスできます。彼ら側の侵害ですべてが露出します。Rediaccは顧客保持の鍵とゼロナレッジアーキテクチャを使用 — 平文も鍵も見ることはありません。
ベンダー管理暗号化が失敗する理由
| ベンダー保持の鍵 | Rediacc(お客様保持の鍵) |
|---|---|
| ベンダーが暗号化鍵を保持 — あなたのデータにアクセス可能 | お客様保持の鍵 — 復号できるのはあなただけ |
| テナント間で共有される鍵インフラ | 自社インフラ上のリポジトリごとの鍵分離 |
| ベンダー侵害で暗号化されたすべてのデータが露出 | ゼロ知識 — 侵害されても使用可能なデータなし |
| 鍵のローテーションにベンダーの関与が必要 | CLIによるセルフサービス鍵ローテーション — 依存関係なし。すべての読み取りが検証されるため、改ざんはすぐに判明します。 |
出典(21)
- Thales, "2025 Cloud Security Study," conducted by S&P Global 451 Research, 2025. "Only 8% of organizations encrypt 80% or more of their cloud data." "57% use five or more encryption key managers."
- IBM Security, "Cost of a Data Breach Report 2024," July 2024. "The global average cost of a data breach reached $4.88 million in 2024."
- Veeam supports external KMS integration for encryption key management including AWS KMS and Azure Key Vault.
- Rubrik supports customer-managed encryption keys via external KMS integration including KMIP-compatible servers.
- Commvault integrates with AWS KMS, Azure Key Vault, HashiCorp Vault, and KMIP-compatible key management servers.
- Druva Enterprise Key Management (BYOK) lets customers use their own AWS KMS keys to encrypt backup data.
- Veeam supports encryption key rotation through KMS integration for compliance with security policies.
- Rubrik supports encryption key rotation through its KMS integration for enterprise key management.
- Commvault supports automated encryption key rotation via the Rotate Encryption Master Keys workflow with configurable intervals.
- Druva supports both cloud encryption key and customer-managed AWS KMS key rotation for security compliance.
- Veeam encrypts backup data at rest using AES-256 encryption with hardware acceleration support.
- Rubrik encrypts all data at rest using AES-256 encryption with software or hardware-based key management.
- Commvault supports AES-256 encryption at rest with hardware-accelerated AES-NI support for backup data.
- Druva encrypts all data at rest with AES-256 using unique per-customer Data Encryption Keys.
- Veeam encrypts all data in transit using TLS for network traffic between backup components.
- Rubrik encrypts all data in transit using TLS 1.2+ between cluster nodes and remote targets.
- Commvault encrypts network traffic in transit using mutual TLS 1.3 with AES_256_GCM_SHA384 cipher suite.
- Druva encrypts all data in transit with TLS 1.2 (256-bit) between customer environment and Druva Cloud.
- Veeam Backup & Replication is deployed on-premises on Windows Server with full customer control over infrastructure.
- Rubrik is deployed as on-premises appliances (r6000 series) with integrated compute, storage, and software.
- Commvault supports fully self-hosted on-premises deployments with CommServe, MediaAgent, and Access Node components.