What happens when you design an encryption system with keys that expire such that when the keys expire the algorithm will refuse to decrypt the data… then you forget to refresh the KEK or the MKEK and the entire data set in the vault is useless? Then what happens when the datastore that holds the keys becomes corrupt and the replication fails?