rypt Client Key Provisioning and Audit Log Handoff (Onboarding)
A sequence with 8 steps: Create the rypt account and confirm the free tier key.
By InnovaAI ResearchPublished
What are the steps?
rypt Client Key Provisioning and Audit Log Handoff (Onboarding)
- 01
Create the rypt account and confirm the free tier key
Verify the account holds one free key with 10,000 operations per month at a vendor cost of $0.00 before any client work begins. The free key's material is held by rypt and wrapped by an HSM root key, so no client-side key material exists to store.
- 02
Generate the API key and record its format
Issue a 44-character token beginning with 'ry_' from the dashboard. Store it in the agency's secret manager, never in the client's repository, because the same token authenticates every encrypt and decrypt call the agency makes on that client's behalf.
- 03
Create a test encryption key and run the round-trip
Use the dashboard's curl, Node, and Python examples to POST plaintext to api.rypt.dev and confirm the returned AES-256-GCM ciphertext decrypts back to the original value. Do not touch client data until this round-trip passes.
- 04
Map the client's sensitive fields to encrypt and decrypt endpoints
Agree on the field list with the client (customer PII, tokens, records) and decide per field whether direct encryption or envelope encryption applies. Envelope encryption is the correct path for files and large objects; direct encryption covers small values.
- 05
Bind ciphertext to the row or tenant with additional authenticated data
Where the client's schema allows it, attach the row or tenant identifier as additional authenticated data so a ciphertext lifted from one record fails to decrypt against another. This is the control that stops a database copy from becoming a usable data set.
- 06
Select the pricing tier that matches the client's operation volume
Extra Wrapped at $3 per month includes 50,000 operations; Software at $10 per month includes 100,000 operations with a dedicated key protected in software. Move a client off the free tier before their monthly volume approaches the 10,000-operation cap, because operations are refused until the counter resets at 00:00 UTC on the 1st.
- 07
Export the append-only audit log and document key custody
Pull the operation log into the client's records and write the key custody policy that names rypt and Google Cloud KMS as holders. This export is the artifact a healthcare, fintech, or e-commerce client hands to its own auditor.
- 08
Hand off the runbook and set the retainer review cadence
Deliver the field map, the tier decision, and the audit log export path to the client's engineering contact, then schedule a monthly check of operation counts against the tier cap so the retainer covers monitoring rather than emergency tier changes.
More on rypt
- StrategyWhy rypt Turns Encryption Into an Agency Retainer Line
- Evaluation Rulerypt Rule: Adopt Only When Client Data Residency and Key Custody Are Contractual Requirements
- Decision FrameworkShould Your Agency Adopt rypt? (Field-Level Encryption for Compliance Clients)
- Failure PatternThe rypt Free-Tier Cap Trap: Why Agencies Fail With rypt on Client Retainers
- Implementation Blueprintrypt Compliance Encryption Retainer Build (6-8 days)