See below for the requirements to use BYOK with SFDC.
Salesforce app requirements
To use SFDC with BYOK, you must create a new connected app in Salesforce.
Only one Connected App and external credential should be used per Salesforce organization
Do not share the Salesforce BYOK connected app credentials.
Do not connect more than one Cryptographic Security Platform Vault cluster to the same Salesforce account.
Salesforce endpoints access requirements
If your organization restricts outbound access to the public internet, you must individually whitelist each Salesforce domain that you want to use.
If a proxy is in use in the network, you can test these endpoints in the Vault application on the Settings > Proxy Settings Vault page.