What is Cloud External Key Manager?
Cloud External Key Manager (EKM) enables the use of cryptographic keys managed in an external key management system to protect data in Google Cloud. Google Cloud communicates directly with the external key management partner for each request, so the key material is never stored in Google’s infrastructure.
Core Features
- External key storage: Keys remain entirely in your own or a partner system
- Transparent encryption: Integration with CMEK-enabled Google Cloud services
- Key Access Justifications: Each request to the external key manager includes a reason for the access
- Partner ecosystem: Certified integrations including Thales, Fortanix, and Futurex
- Connection options: Access over the internet or via VPC networks, including automatable key operations with compatible partners
- Broad service coverage: CMEK integration across a wide range of Google Cloud services in databases, compute, storage, and analytics
Common Use Cases
Regulatory Compliance
Industries such as financial services or healthcare often require encryption keys to be stored outside the cloud provider.
Key Sovereignty
Companies retain complete control over keys. Revoking access makes cloud data immediately inaccessible.
Zero-Trust Security
EKM as part of a zero-trust architecture: Google has no access to unencrypted data without an explicit, logged key access.
Benefits
- Complete control over encryption keys
- Key material never permanently stored in Google infrastructure
- Audit trail via Key Access Justifications for all key accesses
- Supports strict compliance requirements
Note
Cloud EKM requires an external key manager from a certified partner. The additional latency from external calls should be considered for time-critical workloads.
Integration with innFactory
As a certified Google Cloud Partner, innFactory supports you with Cloud EKM: architecture, partner selection, integration, and compliance consulting.
Available Tiers & Options
Standard
- Keys outside Google infrastructure
- Regulatory compliance
- Customer key control
- Additional latency
- External HSM required
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Cloud External Key Manager?
Cloud EKM enables the use of encryption keys held in an external key management system to protect data in Google Cloud. The key material remains entirely outside Google's infrastructure.
Which external key managers are supported?
Cloud EKM supports partners including Thales CipherTrust Manager, Fortanix DSM, and Futurex, as well as other certified partners in the growing EKM partner ecosystem.
Why should I use Cloud EKM?
EKM is suited for scenarios where keys must be stored outside Google for regulatory reasons or key sovereignty requirements.
What happens if the external key manager is unreachable?
Without access to the external key manager, encrypted data cannot be decrypted. High availability of the external system is therefore critical.
How does EKM differ from Cloud HSM?
With Cloud HSM, keys reside in Google-managed HSMs. With EKM, Google Cloud communicates directly with the external key management partner for each request, and the key material stays entirely external.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
