We keep the encryption key stored in plain text files on client offline machine.
Catch: Client machine is encypted with VeraCrypt. Veracript hidden drives, one password is kept by product owner and another password is kept by head of security.
Offline client machine is key for us.
We rotate encryption keys after quarterly security audit.