---
title: "Encryption key management"
canonical: "https://canmyagentuse.com/features/encryption-key-controls"
contentKind: "feature"
locale: "en"
description: "Document provider-managed or customer-managed encryption keys and their scope."
llmSummary: "Encryption key management covers documented provider-managed or customer-managed keys; coverage, rotation, and revocation are recorded as qualifiers."
publishedAt: "2026-08-28T00:00:00.000Z"
updatedAt: "2026-08-28T00:00:00.000Z"
verifiedAt: "2026-08-28"
tags: ["security","encryption","keys","enterprise"]
---

# Encryption key management

Encryption key management covers documented provider-managed or customer-managed keys; coverage, rotation, and revocation are recorded as qualifiers.

- HTML: https://canmyagentuse.com/features/encryption-key-controls
- JSON: https://canmyagentuse.com/api/v1/features/encryption-key-controls.json
- Markdown: https://canmyagentuse.com/features/encryption-key-controls.md

Terminology basis: **Common product term** — https://help.openai.com/en/articles/20000943.

## Current support at a glance

Encryption key management: 3 supported, 0 partial, 0 unsupported, 28 unreviewed across 31 cataloged products.

- Reviewed current products: 3 of 31
- Supported: 3
- Partial: 0
- Unsupported: 0
- Unreviewed: 28
- Not applicable: 0

Unknown or unreviewed means insufficient published evidence; it does not mean unsupported.

This row records the cryptographic controls that apply to the exact harness path. Baseline TLS and provider-managed storage encryption are narrower than customer-managed keys, but even customer keys may exclude logs, indexes, memory, backups, connector data, or third-party tools.

Evidence should identify algorithms or platform guarantees when documented, key ownership and hierarchy, tenant scope, rotation and revocation, service behavior after revocation, recovery, regional restrictions, and plan requirements. Marketing shorthand such as “end-to-end encrypted” needs a precise endpoint and key-holder definition.

## Catalog context

- Category: [security-privacy](/categories/security-privacy.md)
- Terminology basis: Common product term
- Aliases: customer-managed keys, CMK, BYOK, encryption at rest
- Family: [Security and privacy](/features/data-security-controls.md)
- Siblings: [Audit logs](/features/audit-logs.md), [Data residency](/features/data-residency.md), [Data retention controls](/features/data-retention-controls.md), [Offline operation](/features/local-only-mode.md), [Organization policy controls](/features/admin-policy-controls.md), [Secrets management](/features/secrets-management.md), [Training data controls](/features/training-data-controls.md)

## Compatibility assertions

Unknown means insufficient published evidence; it does not mean unsupported.

### ChatGPT (web)

- Harness: [ChatGPT](/harnesses/chatgpt-web.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (web)

- Harness: [Claude](/harnesses/claude-web.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Claude Enterprise CMEK documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): available to eligible Enterprise organizations
  - Constraint (policy): a customer key in AWS KMS, Google Cloud KMS, or Azure Key Vault can replace Anthropic's default encryption for covered team chats, projects, and files
  - Constraint (runtime): the customer controls the key and cloud-provider audit logs record key operations; exact exclusions and changed features are defined in the implementation documentation
  - Evidence: [Anthropic Help Center — Customer-managed encryption keys](https://support.claude.com/en/articles/15505325-what-are-customer-managed-encryption-keys-cmek) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: Eligible Claude Enterprise organizations can replace Anthropic's default encryption for covered chats, projects, and files with a customer key in AWS KMS, Google Cloud KMS, or Azure Key Vault. The customer controls the key and cloud-provider audit logs record Anthropic key operations; the overview delegates the exact coverage and limitations to the implementation docs.
- preview: **Unknown**

### Gemini (web)

- Harness: [Gemini](/harnesses/gemini-web.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot (web)

- Harness: [Copilot](/harnesses/copilot-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok (web)

- Harness: [Grok](/harnesses/grok-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok Bot (desktop)

- Harness: [Grok Bot](/harnesses/grok-bot-desktop.md)
- current: **Unknown**

### Perplexity (web)

- Harness: [Perplexity](/harnesses/perplexity-web.md)
- current: **Unknown**
- preview: **Unknown**

### Le Chat (web)

- Harness: [Le Chat](/harnesses/le-chat.md)
- current: **Unknown**
- preview: **Unknown**

### Devin (web)

- Harness: [Devin](/harnesses/devin-web.md)
- current: **Unknown**
- preview: **Unknown**

### Replit Agent (web)

- Harness: [Replit Agent](/harnesses/replit-agent.md)
- current: **Unknown**
- preview: **Unknown**

### ChatGPT (desktop)

- Harness: [ChatGPT](/harnesses/chatgpt-desktop.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (desktop)

- Harness: [Claude](/harnesses/claude-desktop.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Claude Enterprise CMEK documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): available to eligible Enterprise organizations for covered organization content used from Claude clients
  - Constraint (policy): covered team chats, projects, and files can use a customer key in AWS KMS, Google Cloud KMS, or Azure Key Vault instead of Anthropic's default encryption
  - Constraint (runtime): local desktop-only artifacts are not established as covered; exact exclusions and changed features follow the CMEK implementation documentation
  - Evidence: [Anthropic Help Center — Customer-managed encryption keys](https://support.claude.com/en/articles/15505325-what-are-customer-managed-encryption-keys-cmek) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: Eligible Claude Enterprise organizations can replace Anthropic's default encryption for covered chats, projects, and files with a customer key in AWS KMS, Google Cloud KMS, or Azure Key Vault. The customer controls the key and cloud-provider audit logs record Anthropic key operations; the overview delegates the exact coverage and limitations to the implementation docs.
- preview: **Unknown**

### Cursor (desktop)

- Harness: [Cursor](/harnesses/cursor.md)
- current: **Supported**
  - Target: hosted-observation — 2026-08-28 Cursor CMEK documentation observation; observed 2026-08-28
  - Environment: enterprise-managed
  - Constraint (plan): Enterprise customers contact sales to enable CMEK
  - Constraint (policy): embeddings and Cloud Agent data stored in Cursor infrastructure are encrypted with the customer key, and the customer controls key rotation and access
  - Constraint (runtime): the reviewed page does not establish CMEK coverage for every prompt, model-provider request, external integration, shared link, or local artifact
  - Evidence: [Cursor Docs — Privacy and data governance](https://prod.cursor.com/docs/enterprise/privacy-and-data-governance) — documented; observed 2026-08-28
  - Qualification note 3: Evidence checked 2026-08-28: Cursor Enterprise offers customer-managed encryption keys for embeddings and Cloud Agent data stored in Cursor infrastructure, with customer-controlled rotation and access. The feature does not establish customer-key coverage for every prompt, third-party model request, external integration, or local artifact.
- preview: **Unknown**

### OpenWork Desktop (desktop)

- Harness: [OpenWork Desktop](/harnesses/openwork-desktop.md)
- current: **Unknown**

### Copilot Chat (desktop)

- Harness: [Copilot Chat](/harnesses/vscode-copilot.md)
- current: **Unknown**
- preview: **Unknown**

### Chrome WebMCP origin trial (desktop)

- Harness: [Chrome WebMCP origin trial](/harnesses/chrome-webmcp-preview.md)
- current: **Unknown**

### Windsurf (desktop)

- Harness: [Windsurf](/harnesses/windsurf.md)
- current: **Unknown**
- preview: **Unknown**

### Zed Agent (desktop)

- Harness: [Zed Agent](/harnesses/zed-agent.md)
- current: **Unknown**
- preview: **Unknown**

### Continue (desktop)

- Harness: [Continue](/harnesses/continue.md)
- current: **Unknown**
- preview: **Unknown**

### Cline (desktop)

- Harness: [Cline](/harnesses/cline.md)
- current: **Unknown**
- preview: **Unknown**

### JetBrains AI (desktop)

- Harness: [JetBrains AI](/harnesses/jetbrains-ai.md)
- current: **Unknown**
- preview: **Unknown**

### Warp (desktop)

- Harness: [Warp](/harnesses/warp.md)
- current: **Unknown**
- preview: **Unknown**

### Claude CLI (cli)

- Harness: [Claude CLI](/harnesses/claude-cli.md)
- current: **Unknown**
- preview: **Unknown**

### ChatGPT CLI (cli)

- Harness: [ChatGPT CLI](/harnesses/chatgpt-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Codex CLI (cli)

- Harness: [Codex CLI](/harnesses/codex-cli.md)
- current: **Unknown**
- preview: **Unknown**

### OpenCode (cli)

- Harness: [OpenCode](/harnesses/opencode.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini CLI (cli)

- Harness: [Gemini CLI](/harnesses/gemini-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Aider (cli)

- Harness: [Aider](/harnesses/aider.md)
- current: **Unknown**
- preview: **Unknown**

### Goose (cli)

- Harness: [Goose](/harnesses/goose.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot CLI (cli)

- Harness: [Copilot CLI](/harnesses/copilot-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Amp (cli)

- Harness: [Amp](/harnesses/amp-cli.md)
- current: **Unknown**
- preview: **Unknown**
