AuroraMed v0.2.0 is a synthetic-data pilot. See exactly what's built →

Security, privacy and audit requirements · C0895

How are encryption keys arranged, from the root key down to the data key?

Designed, not yet built

Short answer

The key management part of the specification (REQ-4601) says keys must follow the hierarchy Root -> Master KEK -> Sphere KEK -> Compartment KEK -> DEK with envelope encryption. No. The specification describes it, but the pilot does not include it. Acceptance check: unwrapping chain test; no DEK stored in plaintext.

This is designed, not built.

Specification item
REQ-4601
Specification priority
P0 (of P0 to P3)
Tiers
Small, Medium, Large

Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.

Related answers

See it in context: Key management · Search the help center · Ask a question

See the synthetic-data demo first.Request a demo