Product feature · security-privacy

Encryption key managementCommon product term

Record documented encryption key ownership, scope, rotation, and revocation.

Terminology basis: Common product term. OpenAI — Enterprise Key Management overview

Encryption key management: 3 supported, 0 partial, 0 unsupported, 28 unreviewed across 31 cataloged products.

Markdown · JSON

Explore this familyMore in Security and privacy7 capabilities

Current evidence by product

Can my agent use Encryption key management?

Read across for the answer. 3 of 31 current product columns have reviewed evidence; unreviewed does not mean unsupported.

  • Supported3
  • Partial0
  • Unsupported0
  • Unknown28
  • Not applicable0

Web

9 products

Desktop

13 products

CLI

9 products

Unknown means no public evidence has been reviewed for that product and capability. It does not mean unsupported.

How statuses are assigned

Definition and scope

What this capability means

This row records the cryptographic controls that apply to the exact harness path. Baseline TLS and provider-managed storage encryption are narrower than customer-managed keys, but even customer keys may exclude logs, indexes, memory, backups, connector data, or third-party tools.

Evidence should identify algorithms or platform guarantees when documented, key ownership and hierarchy, tenant scope, rotation and revocation, service behavior after revocation, recovery, regional restrictions, and plan requirements. Marketing shorthand such as “end-to-end encrypted” needs a precise endpoint and key-holder definition.

Traceable compatibility

Assertion ledger

Documentation evidence only. No runtime conformance test is implied.

Claudeweb · current
Supported
Target
2026-08-28 Claude Enterprise CMEK documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planavailable to eligible Enterprise organizations
  • policya customer key in AWS KMS, Google Cloud KMS, or Azure Key Vault can replace Anthropic's default encryption for covered team chats, projects, and files
  • runtimethe customer controls the key and cloud-provider audit logs record key operations; exact exclusions and changed features are defined in the implementation documentation
Evidence
Claudedesktop · current
Supported
Target
2026-08-28 Claude Enterprise CMEK documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planavailable to eligible Enterprise organizations for covered organization content used from Claude clients
  • policycovered team chats, projects, and files can use a customer key in AWS KMS, Google Cloud KMS, or Azure Key Vault instead of Anthropic's default encryption
  • runtimelocal desktop-only artifacts are not established as covered; exact exclusions and changed features follow the CMEK implementation documentation
Evidence
Cursordesktop · current
Supported
Target
2026-08-28 Cursor CMEK documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise customers contact sales to enable CMEK
  • policyembeddings and Cloud Agent data stored in Cursor infrastructure are encrypted with the customer key, and the customer controls key rotation and access
  • runtimethe reviewed page does not establish CMEK coverage for every prompt, model-provider request, external integration, shared link, or local artifact
Evidence
  1. 2. Evidence checked 2026-08-28: Eligible Claude Enterprise organizations can replace Anthropic's default encryption for covered chats, projects, and files with a customer key in AWS KMS, Google Cloud KMS, or Azure Key Vault. The customer controls the key and cloud-provider audit logs record Anthropic key operations; the overview delegates the exact coverage and limitations to the implementation docs.
  2. 3. Evidence checked 2026-08-28: Cursor Enterprise offers customer-managed encryption keys for embeddings and Cloud Agent data stored in Cursor infrastructure, with customer-controlled rotation and access. The feature does not establish customer-key coverage for every prompt, third-party model request, external integration, or local artifact.