About
Enterprise customers that wish to store highly sensitive information in Corsa are offered the Sensitive Data Management feature:- Customers install the Corsa encryption service in their environment.
- Sensitive data is encrypted and decrypted using the customer’s key.
- Encryption occurs on the customer’s side, ensuring full control and compliance.
- The service connects securely to the customer’s AWS KMS.
- End-to-end encryption control.
System Requirements
- A modern Debian distribution (e.g. Ubuntu 24.04)
- Node.js 22.x
- 1 gigabyte of memory
- 1 gigabyte of storage
Networking
- Inbound TLS (typically port 443)
- Outbound traffic can be restricted to TCP port 443 (needed for JWT verification from Auth0 and Corsa)
Keys
There are 4 keys used to encrypt data and handle 2FA:
Corsa currently supports AWS KMS.
Setup
It is recommended to create the keys before launching an instance. See our Terraform guide for an example.Verify Encryption Configuration
Endpoint:GET /v1/platform/encryption-config
Use this endpoint to retrieve the encryption configuration registered for your platform.
REST API
200 response returns the registered configuration. A 204 No Content response means no configuration is registered. This endpoint reports configuration state; it does not test whether your HYOK service is currently reachable.
HYOK is available for enterprise customers. Learn more about Corsa’s security approach or schedule a demo to discuss your encryption requirements.