By using Shield Platform Encryption, you can generate a unique tenant secret for your
org, or generate a tenant secret or key material using your own external resources. In
either case, you manage your own key material: You can rotate it, archive it, and designate
other users to share responsibility for it.
Available in both Salesforce Classic (not available in all orgs)
and Lightning Experience. |
Available as an add-on subscription in: Enterprise,
Performance, and Unlimited Editions. Requires
purchasing Salesforce Shield or Shield Platform Encryption.
Available in Developer Edition at no charge. |
To manage key material: |
Manage Encryption Keys |
When you generate or upload new key material, it becomes the active key. Any
new data is encrypted using this key. However, existing sensitive data remains
encrypted using previous keys, which are now archived. In this situation, we
strongly recommend re-encrypting this data with your active key. You can synchronize
your data with the active key material on the Encryption Statistics and Data
Sync.