Cloud Key Management Service allows you to create, import, and manage cryptographic keys and perform cryptographic operations in a single centralized cloud service. You can use these keys and perform these operations by using Cloud KMS directly, by using Cloud HSM or Cloud External Key Manager, or by using Customer-Managed Encryption Keys (CMEK) integrations within other Google Cloud services.

With Cloud KMS you are the ultimate custodian of your data, you can manage cryptographic keys in the cloud in the same ways you do on-premises, and you have a provable and monitorable root of trust over your data.

Get started for free

Start your proof of concept with $300 in free credit

  • Get access to Gemini 2.0 Flash Thinking
  • Free monthly usage of popular products, including AI APIs and BigQuery
  • No automatic charges, no commitment
Explore self-paced training from Google Cloud Skills Boost, use cases, reference architectures, and code samples with examples of how to use and connect Google Cloud services.

Related videos

Cloud services that have a CMEK integration → https://goo.gle/4iKELPm Protection levels → https://goo.gle/49PFyur Learn how Google Cloud's Customer-Managed Encryption Keys (CMEK) simplify data security by managing key access and inventory. This video

Cloud KMS Keys Best Practices → https://goo.gle/3zOsgRd Encrypt Resources Easily with Cloud KMS Autokey → https://goo.gle/3TWm4x8 Learn how to optimize your use of Cloud Key Management System (KMS) with these best practices for setting up and using

What’s new with Google Cloud? Welcome to our weekly series where we serve you the lowest latency news. This week, we’re talking about data quality, customer managed encryption keys, and Cloud Run targets Find more information on all stories→