KMS

Eviden KMS centralizes cryptographic key management, encryption services, and certificate lifecycle management within a single high-performance platform. Designed for on-premises, cloud, SaaS, and hybrid environments, it enables organizations to maintain full control of their encryption keys, protect sensitive data at scale, and meet sovereignty and compliance requirements.

Overview

High-performance key management for data sovereignty

Organizations need to protect growing volumes of sensitive data while maintaining full control over their encryption keys across on-premises, cloud, SaaS, and hybrid environments. Eviden KMS addresses this challenge by providing a centralized platform for key management, certificate lifecycle management, and high-performance encryption services within a unified and secure environment.
Designed for organizations with stringent sovereignty, security, and compliance requirements, Eviden KMS enables complete control over cryptographic assets while delivering exceptional scalability. Its high-performance architecture supports massive client-side encryption on the fly, processing up to 5 million encrypted messages in less than 5 seconds, allowing organizations to secure data at scale without compromising performance.
Fully open source and built on open standards, Eviden KMS helps organizations simplify cryptographic operations, strengthen data protection, and maintain sovereignty over their most critical digital assets.

Security padlock and circuit board to protect data

Key features

What sets KMS apart

Defense Digital Superiority icon

Centralized key and certificate management

Manage cryptographic assets throughout their lifecycle from a single platform. 

  • Centralized key management
  • Certificate lifecycle management
  • Secure key generation, rotation, and revocation
  • Unified governance across applications and environments
Communication Security icon

High-performance encryption at scale

Designed to secure large volumes of sensitive data without compromising performance.

  • Massive client-side encryption and decryption
  • Up to 5 million encrypted messages processed in less than 5 seconds
  • Optimized for high-throughput environments
  • Consistent performance across cloud, hybrid, and on-premises deployments
IS icon Certified compliance

Certifications

  • Label France Cybersecurity
  • Recognized for excellence in cybersecurity innovation
  • Confirms adherence to high French cybersecurity standards
pqc implementation icon

Sovereignty

Open Source and Developed in France. Combines transparency, flexibility, and digital sovereignty.

  • Fully open-source platform
  • Designed and developed in France
  • No vendor lock-in
  • Extensible architecture and transparent security model
     
IS icon Native Interoperability

Advanced interoperability

Integrates easily with existing security and IT ecosystems.    

  • KMIP 2.1 compliant
  • PKCS#11 support
  • REST API and SDK integrations
  • Compatible with Linux, Windows, and macOS
  • Docker-ready deployment
pqc inventory icon

Embedding standard and modern encryption libraries

Embracing both standard and contemporary cryptographic algorithms, the Eviden KMS boasts an unparalleled breadth of coverage.

  • FIPS 140-3 validated encryption libraries
  • Covercrypt: Post-quantum resistance & access policy
  • Findex: search encryption

Benefits

Modern cloud-ready Key Management System for massive on-the-fly encryption

M

Maintain full sovereignty over your encryption keys

Retain ownership and control of cryptographic assets regardless of where your data resides.    

  • Keep encryption keys under your control
  • Support sovereignty and compliance requirements
  • Reduce dependency on cloud-provider key services
  • Secure sensitive data across all environments
A

Accelerate deployment and integration

Integrate cryptographic services without disrupting existing applications.

  • No need to inject cryptographic libraries into applications
  • Faster deployment and onboarding
  • Reduced development effort
  • Simplified integration into existing infrastructures
S

Scale security as your business grows

Adapt cryptographic services to changing workloads while optimizing costs.

  • Horizontal and vertical scalability
  • High availability architecture
  • Pay-as-you-grow consumption model
  • Cost aligned with actual usage
I

Increased reliability

Developed in Rust, resulting in 70% fewer bugs and enhanced robustness.

Why Eviden

Why choose KMS

High-Performance cryptography without compromise

Eviden KMS combines enterprise-grade key management with exceptional encryption performance, enabling organizations to secure massive volumes of data while maintaining operational efficiency. 

  • Up to 5 million encrypted messages processed in under 5 seconds 
  • Optimized for high-volume workloads
  • Scalable architecture for growing environments
  • Consistent performance across hybrid infrastructures

     

Built for modern enterprise environments

Integrate security seamlessly across applications, clouds, and infrastructures.

  • No application code modification required
  • Unified management of keys and certificates
  • Cloud, SaaS, and hybrid deployment support
  • Rapid deployment and simplified operations
     

Digital sovereignty by design

Maintain full control over cryptographic assets while benefiting from an open and transparent security model.

  • Fully open source
  • Developed in France
     

Future-proof security

Adopt next-generation cryptography while maintaining compatibility with existing infrastructures.

  • Post-quantum ready architecture
  • Support for modern encryption technologies
  • Flexible integration with HSMs and enterprise systems
  • Long-term protection of sensitive information 

FAQ

Frequently asked questions

A Key Management System (KMS) is a centralized platform that manages the lifecycle of encryption keys and certificates. It helps organizations securely generate, store, distribute, rotate, and revoke cryptographic keys while enforcing encryption policies across applications, databases, cloud services, and infrastructures.

The KMS is used to secure data at rest, in transit, and in use by managing encryption keys and certificates across cloud, hybrid, and on-premises environments.

The Eviden KMS can execute cryptographic operations inside Confidential VMs or trusted execution environments, ensuring that sensitive data and keys are protected even during processing.

Yes. It is designed for large-scale encryption workloads, supporting high-throughput processing for distributed systems while maintaining consistent performance across hybrid infrastructures.

Yes. Eviden KMS is designed with a crypto-agile architecture that prepares organizations for the transition to post-quantum cryptography (PQC), ensuring long-term protection against future quantum computing threats.
As part of Eviden, the KMS enables organizations to adopt and manage new cryptographic algorithms without redesigning their entire security infrastructure. This includes the ability to introduce, test, and rotate post-quantum algorithms alongside classical cryptography in a controlled and gradual migration strategy.

Factsheet

Ensuring secure management of keys and certificates

Enhancing security and sovereignty without compromising performance

Eviden KMS is a centralized solution for large-scale, on the-fly encryption/decryption, as well as keys and certificates management, offering advanced features and ensuring exclusive access and control at all times.

 

  • High-performance: Massive on-the-fly client-side encryption with unmatched speed-5 million messages encrypted in just 5 seconds on a 10-core standard server.
  • Data encrypted at the source: Protect your data sovereignty with independent security solutions-no plaintext in public cloud environments.
  • Seamless integration: Secure sensitive data, including workspace, R&D data, HR information, and electronic communications, without disrupting performance or user experience.
  • Streamlined IT management: Automate encryption, simplifying server and IT system management, and empowering system administrators to boost productivity and infrastructure efficiency.

 

Eviden KMS - Key Management System

Other solution

Findex: Search encrypted data without exposing sensitive information

Findex enables fast and efficient queries on encrypted datasets, allowing organizations to preserve data confidentiality while maintaining search capabilities and operational efficiency.

  • Secure exact search: Enables you to find precise matches in encrypted databases (e.g. search for confidential encrypted names or identifiers).
  • Search by prefix or suffix: Offers partial queries, such as “begins with” or “ends with” (e.g. “Mar*” for all items beginning with “Mar”).
  • Massive, high-performance indexing: Designed to index high volumes of data (such as bank transactions or RGPD data), Cosmian findex remains ultra-performant, with latency of just 8 microseconds for searches and 12 microseconds for inserts.
Eviden - Findex

Our team

Corentin Cordier

Corentin Cordier

Cybersecurity Product Owner

charles

Charles Piron

Global Sales Director

How can Eviden support you?

Speak with an expert

Our experts are here to discuss your challenges and design solutions tailored to your organization’s specific needs.