Use one tier model everywhere
Describe key custody consistently as BYOK, CYOK, or HYOK across file, database, mail, calendar, contact, and product data domains.
Give every tenant data domain one encryption control plane.
Velum provides the shared crypto plane behind Vianordis: tenant-scoped key custody, envelope encryption, per-domain tier policy, grant handling, revocation behavior, and audit events for products that need to protect files, rows, messages, calendars, contacts, and other records.
When each application implements its own envelope crypto, KMS routing, grant model, and audit trail, the platform gets inconsistent behavior across files, databases, mail, calendars, contacts, and product-specific stores. Security teams then have to review every management layer separately.
Velum owns tenant key custody, envelope encryption, DEK lifecycle, grants, revocation checks, availability status, and audit events. Management layers keep their domain models and user experience, but they call Velum rather than implementing their own crypto stack.
Velum gives security, compliance, and product teams a common vocabulary and common control plane for how tenant data is encrypted across Vianordis.
Describe key custody consistently as BYOK, CYOK, or HYOK across file, database, mail, calendar, contact, and product data domains.
BYOK and CYOK allow platform-side scanning, indexing, search, rendering, and domain workflows while still enforcing tenant-scoped keys.
HYOK is available where a customer-side proxy can perform the required processing, so zero-knowledge behavior is explicit rather than implied.
CYOK access revocation causes unwrap operations to fail closed, and HYOK prevents Vianordis from ever receiving plaintext keys.
Management layers reuse the same reviewed envelope crypto, KMS routing, grant, rewrap, and audit behavior instead of building separate paths.
Tenants can run different custody tiers simultaneously across domains and, where supported, finer scopes or classifications.
Velum receives the tenant, data domain, and optional scope, then selects the configured BYOK, CYOK, or HYOK tier for that operation.
The plane generates, wraps, unwraps, rewraps, grants, or revokes per-object or per-record data encryption keys according to the selected tier.
Payloads are encrypted with envelope crypto, tier metadata is retained with the record, and key events are emitted to the tenant audit stream.
BYOK covers keys held in Vianordis OpenBao KMS, CYOK covers delegated access to a customer external KMS, and HYOK covers customer-held zero-knowledge keys.
GenerateDEK, UnwrapDEK, Encrypt, Decrypt, RewrapDEK, grant handling, revocation, availability checks, and audit events form one domain-neutral surface.
Policy can differ across files, database records, email, calendar, contacts, and other domains, with optional scope or classification overrides.
Sealed KMS, revoked external access, missing handles, or unavailable key systems return cipher-unavailable errors rather than falling back.
For supported zero-knowledge domains, customer infrastructure performs crypto and necessary processing such as search artifacts or embeddings.
Key operations, grants, rewraps, and revocations are recorded so tenant security teams can reason about access and custody events.
Velum is a platform service consumed by management layers rather than a user-facing file or database application. It is designed to become the common crypto plane for current and future Vianordis products.
Define and explain which domains use platform-held, customer-held, externally delegated, or zero-knowledge key custody.
Map procurement or compliance requirements to concrete BYOK, CYOK, or HYOK choices before product rollout.
Protect object bytes while preserving the option for customer-side HYOK processing where zero-knowledge asset handling is required.
Encrypt sensitive fields or row blobs while retaining server-side query capability for BYOK and CYOK domains.
Apply domain-specific custody policies while recognizing where HYOK would limit server-side search, rendering, free/busy, or deduplication.
Support a verifiable CYOK kill-switch where removing delegated KMS access permanently stops platform decryption.
Velum is intentionally domain-neutral so each management layer can keep its model while sharing the same encryption plane.
Controls how protected data is encrypted and who can access the keys.
Controls how protected data is encrypted and who can access the keys.
Controls how protected data is encrypted and who can access the keys.
Provides the governed place where service data and files are stored.
Stores structured service records in a controlled tenant-aware backend.
Connects communication records so messages can be used in the governed workflow.
Connects scheduling data so time, meetings, and availability stay part of the workflow.
Connects address-book data so people and organizations remain visible in context.
Provides the governed place where service data and files are stored.
Creates reviewable records so important activity can be investigated later.
Keeps access tied to organization accounts, roles, and sign-in policy.
Shows how this service fits into the wider Vianordis environment instead of standing alone.
Lets approved systems connect without ad hoc exports or manual copy-paste.
Velum makes the guarantees explicit: tenant isolation, envelope crypto, per-domain policy, fail-closed behavior, and audit events. HYOK is offered where the corresponding domain can support customer-side processing.
Keys and DEKs are scoped to one tenant, and cross-tenant key use is not part of the model.
Per-tenant CMKs wrap per-object or per-record 256-bit DEKs used for AES-256-GCM payload encryption.
BYOK and CYOK allow platform processing; HYOK does not expose plaintext to Vianordis.
CYOK customer KMS revocation stops unwrap operations and fails closed rather than creating a fallback path.
Tier selection is per data domain and may support finer scopes or classifications where a domain implements them.
Changing an existing domain's custody tier requires re-encryption of existing data.
Velum BYOK is included with every plan. CYOK is listed at €12 per user per month for customer external KMS delegation, and HYOK is listed at €39 per user per month for supported zero-knowledge domains that require customer-side proxy operation.
No. Velum replaces product-specific encryption, KMS routing, and audit logic. DAM or asset catalog services keep their catalog, metadata, search, and embedding value while calling Velum for storage crypto.
BYOK uses a tenant key in Vianordis OpenBao KMS, generated by the platform or imported by the customer. CYOK keeps the root key in a customer external KMS with delegated access. HYOK keeps keys customer-side and makes Vianordis a ciphertext store for supported domains.
Yes. A tenant can run BYOK for one domain, CYOK for another, and HYOK for a supported zero-knowledge domain at the same time.
HYOK removes platform access to plaintext. Any required processing, such as search, malware scanning, rendering, free/busy calculation, or indexing, must happen in the customer's proxy or be unavailable.
Velum fails closed. If the customer KMS no longer unwraps the DEK, Vianordis cannot decrypt the corresponding data and does not fall back to another key.
Yes, but existing records need a re-encrypt migration so each object or record stores the correct tier and wrapped key material.
See how Velum can map your tenant domains to BYOK, CYOK, and HYOK policies while keeping encryption behavior consistent across Vianordis.