Protect Your
Data Power.
Protecting Procurement and Finance data requires more than choosing a storage location. Control over the encryption key matters just as much. Onventis encrypts your data with a Customer Managed Key (CMK) and manages the key in a FIPS Level 3 validated Key Vault controlled exclusively by Onventis. This separates key control from the data itself.
This separation matters for a simple reason: a cloud provider can only access data it can decrypt. Storing the key in a separately managed Key Vault with strict access controls adds a legal and organizational barrier and strengthens protection against external access.
This approach goes beyond data protection. Separating data processing from key control creates clear responsibilities, supports compliance and provides the security architecture expected in regulated environments. Key access and usage can also be logged and audited.
Your data is therefore not only stored in a clearly defined environment. It is also protected by a key that remains outside the hyperscaler’s control. This architecture strengthens the protection of sensitive Procurement and Finance information and gives you greater data sovereignty.
FAQ
What is a Customer Managed Key?
A Customer Managed Key is an encryption key that is not specified by the hyperscaler, but is created, managed and controlled by the customer themselves.
What is a Key Vault?
A Key Vault is a protected key store in the cloud. Cryptographic keys are managed centrally there. Access can be specifically controlled, secured and logged. Azure Key Vault is designed precisely for this purpose.
What is FIPS Level 3?
FIPS Security Level 3 is an internationally established security standard for Hardware Security Modules (HSM). It stands for particularly high requirements for tamper protection and secure key management – especially in regulated industries such as finance, healthcare and the public sector.

