FillTrust

How to answer

Do you support customer-managed encryption keys (BYOK/CMEK)?

The question is about custody, not encryption. Answering "yes, AES-256" answers a different question and a reviewer will notice.

A model answerAnswered “no” from your documents

No. Customer data is encrypted at rest using AES-256 with keys held in our cloud provider's managed key service and rotated annually. We do not currently offer customer-managed or customer-supplied keys.

FillTrust grades an answer like this answered “no” from your documents when your documents support it.

Answered from
Your encryption policy, and whichever architecture document says who holds the keys.
Evidence to attach
Occasionally a diagram showing where keys live. Never the keys, obviously, and never the key management console.
Where it is asked
CAIQ v4.0 · CEK-08SIG Lite

Nearly everyone answers this one wrong on the first pass, because it looks like the encryption question two rows above it and is not.

"Do you encrypt data at rest" asks whether the data is protected. "Do you support customer-managed keys" asks who can turn the protection off. A buyer raising it wants to know whether they can hold the key themselves, rotate it on their own schedule, and revoke it without asking you. Usually that is because their own policy requires it, or because they are thinking about what happens if the relationship ends badly.

No is a normal answer. Customer-managed keys are an enterprise feature with real operational weight: key rotation becomes a shared responsibility, a revoked key means an outage you cannot fix, and a lost key means data you cannot recover. Most companies below a certain size do not offer it, and saying so directly costs less than a paragraph that hedges.

What to put beside the no. Name where the keys actually live and who can reach them: the provider's managed key service, the rotation cadence, and the fact that no individual holds key material directly. That answers the worry behind the question, which is that a key sits in a config file somewhere, even when the feature itself is absent.

If this is a deal blocker, it is a roadmap conversation, not a questionnaire answer. Do not write "planned" unless it is on a plan with a date. "Not currently offered" is a fact; "on our roadmap" is a promise, and a questionnaire is a poor place to make one.

How this one goes wrong

Specific to this question, not general advice.

  • Reading it as "is the data encrypted" and answering yes. The question is about custody, not about encryption, and a yes here means something specific: the customer can hold, rotate and revoke the key.
  • Saying yes because your cloud provider offers CMEK. Your provider supporting it is not the same as your product exposing it, and the gap between those two is a delivery project.
  • Treating a no as a failure. Most companies under a hundred people answer no, and the honest no with the compensating control beside it reads better than a hedged maybe.
  • Forgetting that revocation is the point. A buyer asking this usually wants to know they can cut off access unilaterally. If you cannot offer that, say so plainly rather than describing your rotation schedule at them.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.