Box wants to let businesses control cloud encryption keys “this year”
Box CEO Aaron Levie told Ars last September that the cloud storage company is trying to build a service that would let customers store data in Box data centers but would keep encryption keys in-house.
Context & Ripple Effects
Box's key-custody pledge arrives three weeks after the company filed its S-1 disclosing $124M in full-year revenue against a $168M net loss, with an IPO reportedly expected before the summer. The timing matters: a pre-IPO enterprise vendor needs to neutralize the security objection that keeps regulated buyers out of public-cloud storage.
The plan extends a pitch Aaron Levie has made since at least the December MIT Technology Review profile — making Box 'vital for work' rather than merely a place to stash files — and builds on the consumer-cloud DNA described in the 2012 NYT portrait of the founder. That ReadWrite and ZDNet both carried the announcement the same day signals the key-control question was already live across the trade press.
First-order effects
- Business customers would keep encryption keys inside their own walls while their data sits in Box data centers, removing the single biggest objection IT departments raise when a cloud vendor holds both the content and the means to decrypt it.
- For Box, the feature is a sales asset aimed squarely at the enterprise buyers its S-1 numbers say it must convert profitably before the rumored summer listing.
Second-order effects
- If key custody becomes a checkbox in enterprise storage procurement, rival cloud storage vendors face pressure to match it, shifting competition away from storage volume — which Box had been giving away — and toward who controls the cryptography.
Third-order effects
- The broader pattern is cloud customers clawing back control of a layer they outsourced: data leaves the building, but trust anchors come home. If Box executes, customer-held keys become a standard tier of cloud contracts rather than a premium exception.
The trend: Cloud storage is moving from competing on capacity to competing on sovereignty, with vendors conceding cryptographic control back to enterprise customers.