By default, Xakia manages that encryption key on your behalf — this is the Xakia Managed model.
Customer Managed Encryption Keys (CMEK) is an optional, enterprise-grade feature that lets you supply your own encryption key, stored in your own Azure Key Vault, instead of relying on Xakia's key.
Customer Managed Encryption Keys can also be referred to as Bring Your Own Key (BYOK) - the two terms are interchangeable.
How encryption works in Xakia
When a user uploads a document, Xakia encrypts the file contents before storing them. When the same document is downloaded or previewed, Xakia decrypts it on the way out. The encryption key is what makes that conversion possible.
Without the key, all Xakia holds in storage is an unreadable mess - the original content cannot be recovered.
What changes with CMEK
With the default Xakia Managed model, the encryption key is owned and controlled by Xakia.
With CMEK enabled, the encryption key is owned and controlled by you. Xakia connects to your Azure Key Vault and uses your key to encrypt and decrypt documents. Xakia never stores a copy of your key.
This applies to all document content for the location, including document preview images.
The offboarding guarantee
The primary reason organizations choose CMEK is the certainty it provides at offboarding.
With CMEK, the client retains the ability to revoke Xakia's access to the key at any time. The moment the key is disabled or the connection is severed:
Xakia can no longer decrypt any documents stored for that location.
All stored content becomes permanently inaccessible - not just to external parties, but to Xakia itself.
No action is required on Xakia's side; the client is in complete control.
This gives organizations a cryptographic guarantee that their data cannot be accessed.
Who is this for?
CMEK is available on the Enterprise subscription tier and carries an additional annual fee. It is designed for organizations that:
Operate in highly regulated industries with strict data residency or sovereignty requirements.
Need a verifiable, client-controlled mechanism for data disposal at offboarding.
Have internal security policies that prohibit third-party key custody.
What CMEK does and does not cover
CMEK applies to document content only - uploaded files and their preview images stored within Xakia's document management feature. It does not apply to other data in the system (matter details, metadata, etc.).
