Encryption

Encryption in Devolutions Cloud protects all sensitive configuration and entry data using keys that are owned and managed by your organization, not by Devolutions. By default, secrets stored in Devolutions Cloud are encrypted at rest, and features such as the Encryption service extend this model to SSO scenarios by decrypting your Devolutions Cloud key during login while keeping private keys under your control.

Devolutions Cloud owners can rotate encryption keys and re-encrypt configuration files when required, and must safeguard the emergency kit and private key backups because they are the only way to recover access if keys are lost. In practice, many customers store their emergency kit and private key in a separate secure system, then schedule periodic validation to ensure they can still unlock Devolutions Cloud in a disaster scenario.

Devolutions Forum logo Share your feedback