
6/11/2026
What this post added
This post elaborates on the encryption capabilities within SingleStore Helios, specifically detailing the implementation and implications of Customer-Managed Encryption Keys (CMEK). It explains the architecture of CMEK, which involves using a customer-provided Key Encrypting Key (KEK) to encrypt Data Encryption Keys (DEKs) managed by the cloud provider's KMS. The post highlights the technical aspects of how SingleStore interacts with cloud KMS APIs for encryption/decryption operations and emphasizes the critical importance of key management practices for data sovereignty and the risk of data loss if keys are mishandled or deleted. It contrasts CMEK with platform-managed encryption, providing guidance on choosing the appropriate model based on security and regulatory requirements.