Cloud and SaaS applications are now an integral part of enterprise IT. At the same time, increasingly sensitive information is being stored and processed in applications such as Microsoft 365, Salesforce, and ServiceNow.
The central security question is therefore no longer simply: “Is the cloud secure?” The more important questions are: Where is the data encrypted, who controls the keys, and can the cloud provider process the data in plaintext?
Native SaaS Security uses the integrated security mechanisms provided by the respective cloud provider. Data-Centric Security, by contrast, focuses on protecting the data itself and can use encryption, tokenization, or pseudonymization independently of the underlying cloud infrastructure.
eperi sEcure follows this data-centric approach and protects sensitive data before or at the boundary of the cloud. The solution provides customer-controlled encryption for cloud, SaaS, and web applications.
Native SaaS Security and Data-Centric Security at a Glance
| Criterion | Native SaaS Security | Data-Centric Security |
| Protection mechanism | Provided by the SaaS provider | Independent security layer |
| Encryption location | Dependent on platform and function | Can take place before the cloud |
| Platform dependency | High | Low |
| Key Management | Provider-dependent | Customer control possible |
| Multi-SaaS | No, usually platform-specific | Generally cross-platform |
| Multi-Cloud | Provider-dependent | Architecturally possible |
| Tokenization | Depending on the platform | Possible |
| Pseudonymization | Depending on the platform | Possible |
| Functionality preservation | Platform-dependent | Use-case-specific |
| Data Sovereignty | Architecture-dependent | Core area of application |
Important: The table describes different architectural models. It does not imply that native SaaS security is inherently inadequate.
What Is Native SaaS Security?
Native SaaS Security refers to security capabilities provided directly by the provider of a cloud application.
Examples include:
- Salesforce Shield Platform Encryption
- Microsoft Purview Service Encryption and Customer Key
- Microsoft Purview Double Key Encryption
- ServiceNow Field Encryption
- ServiceNow Field Encryption Enterprise
The advantage of this approach is clear: security capabilities are tightly integrated into the respective application.
Salesforce, for example, offers Shield Platform Encryption, including BYOK support and Search Index Encryption.
Microsoft 365 provides Service Encryption with Microsoft-managed keys or Customer Key. Customer Key enables customers to provide and manage root keys, while Microsoft manages additional keys within the service architecture.
ServiceNow also provides native encryption and key management capabilities with Field Encryption and Field Encryption Enterprise. Field Encryption Enterprise is based on the Key Management Framework and supports capabilities including Customer-Supplied Keys and Key Lifecycle Management.
What Is Data-Centric Security?
Data-Centric Security puts the data itself, rather than the cloud infrastructure, at the center of security.
The underlying principle is:
Security follows the data.
Instead of relying exclusively on a specific cloud platform to protect the data, the information itself is protected.
Typical methods include:
- Encryption
- Tokenization
- Pseudonymization
- Masking
- Policy-based data protection
Data-Centric Security is a strategy in which data is protected independently of where it is stored or processed.
What Is Pre-Cloud Encryption?
Pre-Cloud Encryption refers to an approach in which sensitive data is encrypted before it is transferred to a cloud or SaaS environment.
In simplified form:
Native SaaS Security:
Pre-Cloud Encryption:
eperi sEcure follows this pre-cloud approach while keeping encryption keys under customer control.
BYOK Is Not the Same as Pre-Cloud Encryption
A common mistake in cloud security discussions is to equate key ownership with encryption architecture.
BYOK initially means that a customer provides or controls its own key material.
However, this does not automatically answer the question of where encryption takes place.
Microsoft Customer Key, for example, provides an additional encryption layer for data at rest in Microsoft data centers. Microsoft explicitly states that customers control the root keys, while Microsoft manages additional keys within the service architecture.
The architectural question therefore remains decisive:
Key Control + Encryption Location + Data Processing = Actual Control Model
The entity performing the encryption has access to the plaintext input.
When Is Native SaaS Security Sufficient?
Native security can be the right solution when:
- The platform's integrated security capabilities are sufficient.
- The cloud provider is accepted as a trusted processing environment.
- Protection of data at rest is the primary requirement.
- Deep native integration is desired.
- The possibility of data access by the cloud provider is accepted.
An additional Data-Centric Security layer becomes particularly relevant when:
- Sensitive data should not leave the organization's control zone in plaintext.
- Multiple SaaS applications need to be protected.
- A multi-cloud strategy is being pursued.
- Key management should be organized independently of the cloud provider.
- Regulatory requirements are particularly stringent.
Data-Centric Security with eperi sEcure
eperi sEcure combines encryption, tokenization, and pseudonymization and can be deployed as a security layer between users or the organizational environment and cloud applications. The solution is positioned for Microsoft 365, Salesforce, ServiceNow, and other web and custom applications and is also designed for multi-cloud environments.
The central principle is:
Cloud should be usable without giving up control over sensitive data.
Native SaaS Security vs. Data-Centric Security – Which Approach for Which Requirement?
| Requirement | Native SaaS Security | Data-Centric Security |
| A single SaaS provider | Very well suited | Also possible |
| Protection before entering the cloud | No | Highly suitable |
| Multi-Cloud | Provider-dependent | Highly suitable |
| Customer Key | Partially | Yes |
| Provider-independent security layer | No | Yes |
| Functionality preservation | Provider-dependent | Use-case-specific |
FAQ
What Is Data-Centric Security?
Data-Centric Security protects the data itself, for example through encryption, tokenization, or pseudonymization, rather than securing only the underlying infrastructure.
What Is Pre-Cloud Encryption?
Pre-Cloud Encryption encrypts sensitive data before it reaches a cloud or SaaS environment.
Is BYOK the Same as Data Sovereignty?
No. BYOK increases control over key material, but it is only one part of data sovereignty. Data sovereignty encompasses overall control over data and its processing—including jurisdiction and legal access rights, ownership and control, operational control, administrator and support access, key control, metadata, subprocessors, legal compulsion, and the physical location where data is stored and processed.
The decisive question is therefore not only who owns the key, but also who can access the data technically, operationally, or legally.
Can Data-Centric Security Protect Multiple SaaS Applications?
Yes. Platform-independent approaches can be used across multiple applications and cloud environments. eperi sEcure is explicitly positioned as a multi-cloud security solution.
Do you want to use the cloud without giving up control over your data?
Learn how eperi sEcure protects sensitive data in SaaS and cloud applications.
Newsletter
Sign up for our newsletter and receive regular updates on data protection topics, changes in legislation and the further development of eperi® sEcure.
