A Forbes investigation recently confirmed something that security leaders have quietly worried about for years: A major service provider handed the FBI the BitLocker encryption keys needed to unlock three seized laptops as part of a federal fraud investigation in Guam. It wasn’t a breach. It wasn’t a hack. A 3rd-party provider simply complied with a lawful search warrant, and the data was unlocked within days.
According to court documents reviewed by Forbes, federal investigators openly admitted they lacked the forensic tools needed to break into the encrypted devices. The encryption itself worked perfectly. What failed was the architecture, the decision to store recovery keys in the cloud by default.
The cloud service provider confirmed to Forbes that it receives roughly 20 such requests per year from law enforcement. Twenty times a year, encryption keys stored in a cloud provider’s infrastructure are handed over under legal compulsion. And when that cloud provider holds your keys, neither your encryption nor your legal team can stop it.
This cloud-era data sovereignty story has direct implications for every enterprise storing sensitive files in the cloud today.
“The keys give the government access to information well beyond the time frame of most crimes, everything on the hard drive”
— Jennifer Granick, surveillance and cybersecurity counsel at the ACLU
The Illusion of Encryption in the Cloud
Most organizations believe that encrypting data before uploading it to the cloud means the cloud provider cannot read it. That assumption holds only if the encryption keys are managed entirely outside the provider’s control. When a cloud provider manages or stores your keys — even as a convenience feature — you have not encrypted your data from the provider. You have simply added a layer of access management that a valid court order can dissolve.
This architectural problem applies to any organization that encrypts cloud-stored files with keys managed by the same cloud platform. AWS Key Management Service, Azure Key Vault, and Google Cloud KMS are powerful, well-engineered products. But when subpoenaed, those providers face a legal reality: they hold the keys, and the law can compel them to produce them without notifying the data owner.
The question enterprises need to answer is not whether their data is encrypted. The question is: who controls the keys?
What True Data Sovereignty Looks Like
True data sovereignty means you retain exclusive control over your encryption keys: not your cloud provider, not your SaaS vendor, not a 3rd party, not any government that serves that vendor a warrant. Achieving this in a multi-cloud environment requires two things working in concert: client-side file encryption and independently managed key infrastructure.
This is precisely the architecture that Utimaco LAN Crypt File and Folder Encryption, paired with the Utimaco Enterprise Secure Key Manager (ESKM), delivers.
LAN Crypt File and Folder Encryption encrypts files and folders directly on the user’s device before any data is transmitted or stored anywhere — on-premises, in Azure, AWS, Google Cloud, or any combination of cloud environments. The encryption is persistent and transparent. Files travel encrypted. Files rest encrypted. When a file is opened by an authorized user, decryption happens locally on that device. The cloud storage layer — whichever provider it is — never sees plaintext, and critically, never holds a key.
This is client-side encryption in its purest form. The cloud provider becomes a secure, cost-effective storage medium for ciphertext it cannot read, cannot decrypt, and cannot hand over in any meaningful form, even under legal compulsion.
The Key to the Keys: Utimaco ESKM
ESKM provides a single pane of glass for all cryptographic keys across every environment, whether on-premises or in the cloud. It supports over 2 million keys and more than 25,000 clients, with broad interoperability through OASIS KMIP, RESTful APIs, and KMS integrations. The ESKM integrates directly with LAN Crypt File and Folder Encryption, providing centralized storage and management of every client-side encryption key used to protect your files — from a deployment that you own and control, not your cloud provider.
Additionally, granular role-based access controls and comprehensive audit trails give compliance teams full visibility into who accessed which keys and when, which is precisely what regulators under GDPR, HIPAA, PCI DSS, and DORA look for in compliance audits.
Multi-Cloud Without Multi-Risk
The multi-cloud reality for most enterprises today is not a choice between providers — it is all of them simultaneously. Finance data in AWS. Collaboration files in Microsoft 365. Engineering repositories in Google Cloud. Backup archives in a third provider. Each of those environments represents a separate legal and security jurisdiction, attack surface, and risk profile.
LAN Crypt File and Folder Encryption with ESKM was built for exactly this architecture. Because encryption happens on the client device and key management is centralized in ESKM, the security model is identical regardless of which cloud environment a file ends up in. A sensitive contract in OneDrive and the same contract archived in S3 are both encrypted with keys that live only in your ESKM deployment. Neither provider can be compelled to hand over the keys.
A Decision That Belongs to You
The service provider acknowledged after the Forbes report that customers are best positioned to decide how to manage their keys. We agree, and we built Utimaco LAN Crypt File and Folder Encryption and ESKM to make that decision actionable.
With LAN Crypt File and Folder Encryption client-side encryption and ESKM-managed keys kept outside the cloud, that conversation simply never happens because the cloud provider never had them in the first place.
Prêt à assurer votre avenir numérique ?
Rejoignez plus de 500 entreprises mondiales et institutions gouvernementales qui font confiance à Utimaco pour leur infrastructure de sécurité critique.
Contacter le service des ventesYour download request(s):

Your download request(s):

About Utimaco's Downloads
Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).
For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.
A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.