- Secures the keys on which all encryption ultimately depends
- Automates rotation so keys change regularly without manual error
- Centralises control, audit, and revocation of cryptographic keys
- Separates key custody from data, limiting the blast radius of a breach