Learn about managing your encryption keys in Prisma AIRS.
| Where Can I Use This? | What Do I Need? |
- Prisma AIRS AI Runtime: API
security
|
|
Prisma AIRS encrypts all of your AI security scan data — including prompts,
model responses, and tool calls — before storing it. This feature gives you direct
control over that encryption key. With this functionality you can:
Rotate - this creates a new key version and promotes it to
primary; future uploads use the new version, and existing data remains
accessible via the old version.
Disable (per key version) - this disables a specific key
version by number; data encrypted with that version becomes inaccessible
within approximately 1 minute.
Enable (per key version) - this re-enables a previously
disabled key version, restoring read access to data encrypted with it.
You can do this all without opening a support ticket:
What gets encrypted: All raw scan content associated with
your tenant — prompts, model responses, and tool call data stored by Prisma
AIRS.
How keys work: Your data is protected by an encryption key
unique to your tenant. When you view a security violation in Strata Cloud
Manager, that key is used to decrypt your data for display. If the key is
disabled, violation data becomes inaccessible.
Automatic rotation: Your encryption key rotates
automatically every 90 days. The operations in this guide let you act
outside that schedule when your security posture requires it.
Who can do this: You need the appropriate role in Strata
Cloud Manager. Contact your administrator if you don't see the Data
Encryption settings panel.
Encryption key management is available in all
regions.
Frequently Asked Questions
Does rotating my key affect my existing scan data?
No. Your existing scan data stays fully accessible after a rotation. Only
new data is protected by the new key version.
What happens to new scans when I disable my primary key?
Disabling the primary key version does not automatically create a new key;
new scans will fail until you either re-enable that version or rotate to create a
new primary key.
How quickly does disabling take effect?
Within approximately 1 minute of disabling the key version, the data
encrypted with that specific key version becomes inaccessible.
Can I undo disabling a key version?
Yes. Use the Enable a disabled key version action to re-enable your
key and regain access to your data.
My key was disabled and I can't see violation details. What should I
do?
Go to Configurations › Data Encryption and use the Enable Key
action on the relevant Key Version. If you did not intentionally disable your key,
contact your security team before restoring.
How do I know when my key will next rotate automatically?
The Data Encryption panel shows the Next Rotation
Date.
Do I need to do anything for automatic rotations?
No. Automatic rotations happen in the background every 90 days without any
action required on your part.
Who can see and manage encryption keys?
Your Strata Cloud Manager administrator controls who has permission to
rotate, disable, or enable keys. Viewing key health is available to all roles.
Rotating the key and disabling or enabling a key version require an elevated
permission.
To locate your encryption keys: