BTIT: Cryptographic key management

Cryptographic key management covers how encryption keys, secrets, tokens and certificates should be protected.

Customer guidance

  • Never paste private keys, API secrets or tokens into ordinary support tickets unless explicitly requested through an approved secure process.
  • Rotate exposed or suspected-compromised keys immediately.
  • Use separate credentials for production, testing and development.
  • Limit access to keys to only those who need it.

For support

If a certificate, token or key appears compromised, raise the request as urgent and include which system or service is affected.