Home > Manage SigningHub Admin Configurations > Configure Data Security

Configure Data Security

By default all sensitive data held by SigningHub (including user documents and other information) is encrypted using a uniquely generated AES-256 symmetric Data Encryption Key (DEK). When stored this symmetric DEK is protected with a higher-level AES-256 key known as the Key Encryption Key (KEK).  In turn the KEK is managed directly inside SigningHub using a secure software process. 

For an even higher-level of security it is possible to hold the KEK inside a tamper-protected Hardware Security Module (HSM). To achieve this SigningHub relies on its underlying Ascertia ADSS Server component and its associated HSM to provide the required KEK services.

For this create an ADSS Server connector in the SigningHub Admin Connectors area.
Now generate a key with the "Key Encryption Key (KEK)" Purpose in 
the ADSS Server instance associated inside the ADSS Server connector, see details how. After generating the key, configure it inside the same ADSS Server instance, see details how.

Configure your data security
  1. Click the "Configurations" option from the left menu.
  2. Click the "Data Security" option.
    The Data Security screen will appear.
  3. Tick the "Enable Key Encryption Key (KEK) to secure documents/links/passwords" check box to enable the SigningHub DEK encryption/decryption through the ADSS Server managed KEK. A drop down will appear to select the encryption server.
    If you want to use the default security (i.e. based on the SigningHub software managed KEK), keep this check box un-ticked.
  4. Now select an encryption server (i.e. ADSS Server connector). The ADSS Server connectors are managed through the connectors section, see details.
  5. Click the "Save" button from the screen bottom.
  6. Click the "Publish Changes" button from the top right corner, to make these configurations take effect.



See also
Configure Global Settings
Manage Connectors
Manage Authentication Profiles
Manage Certification Profiles
Manage Signing Profiles
Manage Verification Profiles
Manage Virtual ID Profiles
Configure Auto Signing of Workflow Evidence Report
Configure Service Agreements
Configure Document Settings
Configure Billing Facility
Configure SigningHub License
Configure SigningHub Branding
Configure SigningHub Instances
Update Redis Configurations
Publish Your Configurations