Storage

Store and migrate certificate assets across Sia and AWS using provider managed or self managed storage.

Overview

Each X.509 asset lives within a single storage provider at any given point in time. SecuriTLS lets you use, store, and migrate X.509 assets between multiple storage providers.

Provider managed storage

Provider managed storage is managed and provided by SecuriTLS.

Self managed storage

Self managed storage is managed by you and is available to Solo, Team, Business, and Enterprise users. Free workspaces use provider managed storage.

Self managed storage controls where encrypted certificate assets are stored. It does not, by itself, change the key custody model. Storage encryption still uses a SecuriTLS generated DEK unless Business or Enterprise BYOK is configured.

Sia storage

Built on Sia, SecuriTLS uses decentralized storage by default. Sia distributes fragmented, encrypted data across a global network of independent storage providers. Data is not stored on the blockchain.

  • Label or name optional
  • Bucket name
  • API endpoint
  • API password sensitive

AWS storage

AWS self managed storage supports access key based setup and role based setup.

  • Label or name optional
  • AWS region
  • Bucket name

Role based AWS setup

Role based setup uses a cross account IAM role that SecuriTLS can assume. The role can optionally require an external ID. Use your bucket level and object level S3 permissions as described in the README.