Master key (KEK)
Data-encryption key (DEK)
Protected data object
Exposed data object
โ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.
Every major cloud key-management service protects data the same way: a hardware-guarded master key (the KEK) never touches bulk data directly โ it only wraps a unique, per-object data-encryption key (DEK), which does the actual work. This simulator renders that hierarchy in 3D: a central KEK, a ring of DEKs, and the data objects they protect. Rotate the master key to see re-wrapping happen without touching a single byte of ciphertext, or flip envelope encryption off to watch a single shared key turn one leaked DEK into a total breach instead of a contained one. Live readouts track the KEK version, the number of unique DEKs in play, and the resulting blast radius after a simulated leak.