Skip to content
Back to skills

Shield Kms Byok Setup

ASecurity

Configure Shield Platform Encryption with customer-supplied (BYOK) or customer-held (Cache-Only Key Service) tenant secrets, rotate them, and recover. NOT for Classic Encryption or field masking.

  • 15 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added June 1, 2026
ai-agentsrustgospringawsazureapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 7 files and shows the line behind each finding

Scanned June 1, 2026

npx -y skills add PranavNagrecha/AwesomeSalesforceSkills --skill shield-kms-byok-setup --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Shield Kms Byok Setup?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Shield Kms Byok Setup
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/pranavnagrecha-shield-kms-byok-setup/badge)](https://www.skillsdirectory.com/skills/pranavnagrecha-shield-kms-byok-setup)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: shield-kms-byok-setup
description: "Configure Shield Platform Encryption with customer-supplied (BYOK) or customer-held (Cache-Only Key Service) tenant secrets, rotate them, and recover. NOT for Classic Encryption or field masking."
category: security
salesforce-version: "Spring '25+"
well-architected-pillars:
  - Security
  - Reliability
triggers:
  - "shield byok setup"
  - "cache only key service"
  - "rotate tenant secret"
  - "customer managed keys salesforce"
tags:
  - shield
  - encryption
  - byok
  - kms
inputs:
  - "KMS (AWS KMS / Azure Key Vault) endpoint"
  - "key material"
  - "org Shield license"
outputs:
  - "Tenant secret rotation policy"
  - "CMK setup runbook"
dependencies: []
version: 1.0.0
author: Pranav Nagrecha
updated: 2026-04-28
---

# Shield Platform Encryption — BYOK / KMS Setup

Shield BYOK lets you upload your own 256-bit tenant secret; Cache-Only Key Service keeps the key in your own KMS, fetched by Salesforce on demand. Both require Shield Platform Encryption and careful operational processes: rotation, destroy tests, and KMS availability SLOs.

## Recommended Workflow

1. Enable Shield Platform Encryption and identify fields/files/chatter that require probabilistic vs. deterministic encryption.
2. Generate a 256-bit key in your KMS; for BYOK, derive and upload; for Cache-Only, configure named credential + callback.
3. Rotate tenant secret quarterly via Setup → Platform Encryption → Key Management.
4. Run a destroy-key test in a sandbox to prove you can revoke access (records become unreadable).
5. Document KMS availability SLO — if your KMS is down, Salesforce cannot decrypt in the Cache-Only flow.

## Key Considerations

- BYOK key material never leaves Salesforce after upload; Cache-Only keys never enter Salesforce's durable storage.
- Deterministic encryption is required for filter equals queries — trades strength for functionality.
- Rotation re-encrypts newly written data only; historical data stays under the previous tenant secret until you run Encryption Key Rotation batch.
- Cache-Only: callback latency adds to every decrypt; measure in load tests.

## Worked Examples (see `references/examples.md`)

- *BYOK tenant secret upload* — Healthcare provider, HIPAA.
- *Cache-Only Key Service with AWS* — Financial services firm refuses to upload key material.

## Common Gotchas (see `references/gotchas.md`)

- **Destroy-key not tested** — On a real incident nobody can prove revocation works.
- **KMS outage = decrypt failure** — User pages go blank; agents cannot read records.
- **Mix of deterministic and probabilistic** — SOQL filter on a field silently fails to return results.

## Top LLM Anti-Patterns (full list in `references/llm-anti-patterns.md`)

- Using default tenant secret indefinitely
- Encrypting a field and then using SOQL LIKE on it
- No runbook for KMS outage

## Official Sources Used

- Apex Developer Guide — Sharing — https://developer.salesforce.com/docs/atlas.en-us.apexcode.meta/apexcode/apex_bulk_sharing_understanding.htm
- Salesforce Security Guide — https://help.salesforce.com/s/articleView?id=sf.security.htm
- Shield Platform Encryption — https://help.salesforce.com/s/articleView?id=sf.security_pe_overview.htm
- Session Security Levels — https://help.salesforce.com/s/articleView?id=sf.security_hap_session.htm
- CSP and Trusted URLs — https://help.salesforce.com/s/articleView?id=sf.security_csp_overview.htm
- API Only User Profile — https://help.salesforce.com/s/articleView?id=sf.users_profiles_api_only.htm
- Privacy Center and DSR — https://help.salesforce.com/s/articleView?id=sf.privacy_center_overview.htm

Files in this skill

  • SKILL.md3.6 KB
  • references/examples.md895 B
  • references/gotchas.md829 B
  • references/llm-anti-patterns.md330 B
  • references/well-architected.md1016 B
  • scripts/check_shield_kms_byok_setup.py926 B
  • templates/shield-kms-byok-setup-template.md570 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…