Features
The entitlement catalog that turns platform capabilities on or off per edition.
The feature model
A feature is a named entitlement that turns a platform capability on or off (or sets a numeric limit). Each feature has a value type and belongs to a category:
| Aspect | Detail |
|---|---|
| Value type | Boolean · Numeric · Text |
| Numeric convention | -1 = unlimited · 0 = none (fail-closed) · n = maximum |
| Resolution | A tenant\'s value comes from its edition; anything not explicitly granted resolves to a safe, fail-closed default |
| Coming-soon | Capabilities marked coming-soon appear for visibility but cannot be selected or enabled |
Feature values live on editions (there are no per-tenant overrides), so changing what a tenant can do means changing its edition.
Catalog by category
| Category | What it entitles |
|---|---|
| Key management | Whether key management is enabled, how many keys are allowed, and which key algorithms may be used (RSA, elliptic-curve, AES, HMAC, post-quantum) |
| Vault management | Whether vaults are enabled, how many, and which vault providers are available (software, DuoKey HSM, Securosys, the major cloud KMS providers, HashiCorp and more) |
| PKI | Whether PKI is enabled, how many certificate authorities are allowed, external-CA support, and enrolment protocols (EST, SCEP, ACME, CMP, OCSP) |
| PQC | Post-quantum readiness and the number of PQC endpoints |
| Applications | Whether apps are enabled, how many, and which product integrations are available |
| Identity / SSO | Whether SSO is enabled and which identity providers (Azure AD, Okta, Keycloak, UAE Pass, Ping Identity, RSA SecurID Access, ForgeRock) |
| Access control | Attribute-based access policies |
| SSH Certificate Authority | Whether the SSH Certificate Authority module is enabled, how many CAs and active certificates are allowed, and whether the live PKCS#11 signing bridge may be enrolled |
| MCP | Whether the MCP interface is enabled, which capability packs it exposes, and its usage limits |
| Platform | Cross-cutting capabilities such as webhooks, KMIP and the maximum number of users |
How features gate capabilities
Whether a capability exists for a tenant is decided by its edition. Before an operation runs, the platform checks the corresponding entitlement centrally, so a capability the edition does not grant is simply unavailable.
Core administrative surfaces (sign-in, users, roles, settings, tenants, editions, billing, dashboards, audit and activity logs, notifications, organizational units and features) are always available and never feature-gated.
Features decide whether a capability exists for the tenant's edition; permissions (see Administration) decide whether this user may use it. A call must pass both.
Coming-soon features
A set of features is marked coming-soon: they appear in the catalog for visibility but cannot be selected or enabled. Treat them as roadmap, not available capability.
Product catalog
The platform ships a broad catalog of products and integrations a tenant can deploy. Each app is scoped to a tenant and, optionally, to an organizational unit.
| Group | Products |
|---|---|
| Microsoft 365 / DKE | DKE 365, ADFS, SharePoint, Exchange, Purview DLP |
| Database TDE | Oracle TDE, MySQL TDE, Percona PostgreSQL, MongoDB CSFLE, SQL EKM |
| Cloud KMS / BYOK | Azure EKM, AWS XKS, OCI EKMS, Google CSE, Snowflake tri-secret |
| SaaS BYOK | Salesforce, ServiceNow, Slack, Zoom, Box, GitHub, Atlassian, Zendesk, Workday, ADP, SAP Data Custodian, Genesys |
| Data security posture | Varonis, Cyera, Wiz, Netwrix |
| Network / SSL | Cloudflare keyless, F5 BIG-IP, Imperva WAF, Skyhigh SWG |
| Signing | PDF signing, code signing (Git, GitLab, SignTool, Docker, kernel, JAR, Office macro), key attestation |
| Interfaces | KMIP, REST API, custom SDK, HashiCorp / OpenBao, vault sync, customer key, KMS client |
Each product integrates over standard interfaces (such as REST and KMIP) and common authentication methods (such as API keys, OAuth2, mutual TLS and identity-provider sign-in), and exercises only the cryptographic operations it needs (for example encrypt, decrypt, sign, verify, wrap and unwrap).
DKE 365 and Oracle TDE are examples of apps from the catalog above. PKI and PQC are core platform modules rather than apps. KMIP is available both as a platform gateway and as an interface an app can use.
API reference
Feature definitions are read-only; their values are managed on editions, where each edition sets what its tenants are entitled to.