Skip to main content

About

Enterprise customers that wish to store highly sensitive information in Corsa are offered the Sensitive Data Management feature:
  • Customers install the Corsa encryption service in their environment.
  • Sensitive data is encrypted and decrypted using the customer’s key.
  • Encryption occurs on the customer’s side, ensuring full control and compliance.
  • The service connects securely to the customer’s AWS KMS.
  • End-to-end encryption control.

System Requirements

  • A modern Debian distribution (e.g. Ubuntu 24.04)
  • Node.js 22.x
  • 1 gigabyte of memory
  • 1 gigabyte of storage

Networking

  • Inbound TLS (typically port 443)
  • Outbound traffic can be restricted to TCP port 443 (needed for JWT verification from Auth0 and Corsa)

Keys

There are 4 keys used to encrypt data and handle 2FA: Corsa currently supports AWS KMS.

Setup

It is recommended to create the keys before launching an instance. See our Terraform guide for an example.

Verify Encryption Configuration

Endpoint: GET /v1/platform/encryption-config Use this endpoint to retrieve the encryption configuration registered for your platform.
REST API
A 200 response returns the registered configuration. A 204 No Content response means no configuration is registered. This endpoint reports configuration state; it does not test whether your HYOK service is currently reachable.
HYOK is available for enterprise customers. Learn more about Corsa’s security approach or schedule a demo to discuss your encryption requirements.