Key recovery material

Identifies key-recovery and escrow references, while reserving enforcement for records that contain a structured recovery value. A phrase alone is discovery-only; system identity and custody/escrow fields distinguish a high-confidence recovery-material record.

Type
regex
Engine
boost_regex
Confidence
medium
Confidence justification
structural regex with domain-specific anchors and constrained context replaces phrase-only marker. Added context gating and exclusion rules improve precision and reduce incidental matches.
Detection quality
Topic false positive
Jurisdictions
global
Regulations
GDPR, Criminal Code Act 1995 (Cth), NDB Scheme (Cth), SOCI Act 2018 (Cth), TIA Act 1979 (Cth)
Data categories
credentials, security
Scope
wide
Risk rating
8
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported

Pattern

(?is)\b(?:key\s+recovery|recovery\s+key|escrow\s+key|break-glass)\b

Corroborative evidence keywords

key recovery, recovery key, escrow key, break-glass, hsm, kms

Proximity: 240 characters

Should match

Should not match

Known false positives

References