Customer-managed encryption keys (BYOK) in Adobe Acrobat Sign - New

Last updated on Apr 18, 2026
Alert

This article contains prerelease information. Release dates, features, and other information are subject to change without notice.

Use a customer-managed key to encrypt agreement data at rest for an account.

Customer-managed encryption keys (BYOK) allow enterprise accounts to configure a customer-provided key for encryption at rest of agreement data and related files. When enabled, Adobe Acrobat Sign uses the configured key to encrypt supported stored file content without impacting SLA, disaster recovery, or data residency. 

BYOK associates an account with a customer-managed encryption key used for encryption at rest.

BYOK is configured at the account level and applies to new content created after it is enabled. Existing agreements remain encrypted with Adobe-managed keys unless re-encryption is performed in later phases.

Scope and availability

  • Available for enterprise-tier accounts.
  • Configured at the account level only; not available at the group level.
  • Requires a customer-managed key in AWS Key Management Service (KMS) for initial release. 

What BYOK does

  • Associates an account with a customer-managed encryption key.
  • Uses envelope encryption, where:
    • Agreement data is encrypted with a data encryption key (DEK).
    • The DEK is protected by a customer-managed key.
  • Supports key lifecycle operations including onboarding, rotation, suspension, and destruction. 
Diagram showing envelope encryption in BYOK: agreement data is encrypted using a data encryption key (DEK), and the DEK is protected by a customer-managed key in a key management service.
Conceptual view of BYOK envelope encryption. Agreement data is encrypted with a data encryption key (DEK), and the DEK is protected through the customer-managed key configuration.

What content is encrypted

When BYOK is enabled, encryption applies to supported stored file content created after enablement:

  • Agreement PDFs
  • Templates
  • Thumbnails
  • Temporary files

What is not included

  • Existing agreements created before enablement remain encrypted with Adobe-managed keys.
  • Search index data is not encrypted with customer-managed keys.
  • Data in transit is not affected and continues to use existing encryption mechanisms.

Data access behavior

  • Access to encrypted data depends on the availability and validity of the configured key.
  • If the key is unavailable, encrypted data cannot be accessed.

When the key becomes unavailable (for example, disabled, revoked, or credentials are invalid):

  • The system continues to allow access for a limited time based on the configured TTL.
  • After the TTL expires (5–60 minutes, default 60), access to BYOK-encrypted content is blocked. 

Key lifecycle operations

Key lifecycle actions affect access to encrypted data.

Destroy is an irreversible action that permanently removes access to encrypted data.

Administrators can perform the following actions on the configured key:

  • Onboard (Enable) – associates the account with a customer-managed key.
  • Rotate or revert – updates or restores the key version used for encryption.
  • Suspend – blocks all encryption and decryption operations for the account.
    • Access to BYOK-encrypted content is prevented while the key remains suspended.
  • Destroy – permanently removes access to encrypted content.
    • This action is irreversible. BYOK-encrypted data cannot be recovered after the key is destroyed.

Key management responsibility

Customers are responsible for:

  • Creating and maintaining the customer-managed key in AWS KMS
  • Providing access credentials to Acrobat Sign
  • Maintaining key availability and permissions
  • Managing key lifecycle actions such as rotation or revocation

Important considerations

The following conditions affect how BYOK encryption behaves and when encrypted data can be accessed:

  • If the customer-managed key becomes unavailable, BYOK-encrypted agreements become inaccessible.
  • Cache TTL (5–60 minutes, default 60) determines how quickly key status changes affect access to encrypted data after the key becomes unavailable.
  • Only new agreements created after enablement use BYOK encryption in the initial release.
  • Existing agreements remain encrypted with Adobe-managed keys unless re-encryption is performed in later phases.
  • BYOK configuration is applied at the account level and cannot be scoped to individual groups.