API-driven encryption and signing. Encrypt data, sign payloads, and generate HMACs with fine-grained IAM, project scoping, and full audit logging.
Thalassa Cloud KMS gives you a managed way to create, rotate, and use cryptographic keys across your cloud regions. Keys run in regional OpenBao Transit clusters so crypto stays close to your workloads and within your chosen geography — with organisation, region, and project scoping aligned with the rest of the platform.
Generate platform keys or import your own (BYOK), choose from symmetric, signing, and HMAC algorithms, and configure automatic rotation — all from the Thalassa Cloud console.

Encrypt and decrypt application data with industry-standard algorithms through a simple API and console.
Sign payloads, verify signatures, and generate keyed hashes for certificates, tokens, and DNSSEC.
Rotate keys on a schedule, import external key material, and control deletion with a recovery window.
Separate roles for admin, operator, and auditor with per-action policies and platform-wide audit logging.
Explore the KMS documentation for getting started, key types, encryption, rotation, BYOK, access control, and integrations with Secrets Manager and DNS DNSSEC.
European Public Cloud
Deploy and manage your cloud-native applications with our European based public cloud. Access powerful APIs, Kubernetes orchestration, and DevOps tools designed for modern infrastructure.
EU Data Sovereignty
Terraform & REST API
Self-Service Kubernetes as a Service
NVMe Storage, CPU and network
Code. Ship. Scale. • Pay-as-you-go pricing