Bring Your Own Key (BYOK) comes to Europe

For European organizations, keeping sensitive data under your own control can be an organizational — and sometimes a legal — requirement. BYOK is here to help.

September 29 2026 by

Mignon Wagner

A series of old-fashioned brass keys on a shiny gray surface to symbolize Jamf Bring Your Own Key.

After launching Bring Your Own Key (BYOK) in North America in spring, we're now expanding BYOK to Europe for organizations hosting Jamf Pro in the Jamf Cloud in Frankfurt, Germany.

What is BYOK? How does BYOK work?

Bring Your Own Key, also known as CMK (Customer Managed Keys), lets customers provide and manage their own encryption keys for data stored in Jamf Cloud. Jamf already encrypts data at the disk and application level. BYOK goes a step further, putting the application-level encryption key itself in your hands rather than ours. It allows you to generate a key using your own key management system, and Jamf's cloud-hosted services use that key to encrypt and decrypt your data.

BYOK integrates with four key management systems you may already run:

For more details, read our introductory blog on BYOK and dive into technical details in product documentation.

Built for European data protection requirements

BYOK was designed with regulated industries in mind, and for organizations in Europe, that usually means GDPR+ with industry-specific frameworks layered on top. But the more common conversation we're having with European customers right now isn't about a specific regulation. It's about the gap between data residency and data sovereignty: choosing a Frankfurt data center solves where your data sits, but not which laws govern the company operating around it.

BYOK closes that gap for Jamf Pro data. Because the encryption key lives with you and not with Jamf, we hold no key to hand over — not even in response to a subpoena or a request under the US CLOUD Act. What Jamf can produce depends on whether your organization has an active connection to its key management system at the time of the request; you retain the ability to cut that connection and with it Jamf's ability to access your data in usable form. This builds on a commitment we already make to every customer: we don't hand over customer data to a government agency unless legally compelled to, and where we're permitted, we'll notify you so you can respond directly.

A few things worth calling out:

Jamf BYOK is hosted in Frankfurt.

BYOK in Europe runs out of our Frankfurt hosting region. If your organization is based in the UK or elsewhere in Europe and wants to use BYOK, you may need to migrate your Jamf Cloud hosting to this region.

Data currently covered

At launch, this service can protect Jamf Pro and Declarative Device Management (DDM) data. Jamf plans to expand to additional cloud-hosted solutions in the future.

It's about control, not just compliance.

Auditors and regulators care about compliance checkboxes. Your security team cares about something more basic: does anyone at Jamf have a way to decrypt our data without us knowing? With BYOK, the honest answer is no — we don't hold the key, so we can't unlock the data without continued access to your encryption keys.

Get started

BYOK is available now for new and existing customers hosting their Jamf instances in Jamf Cloud's Frankfurt datacenter, excluding Jamf Premium Cloud Plus or StateRAMP environments. Reach out to your Jamf representative to discuss eligibility.

Not with Jamf yet? Request a free trial today.

Tags: