Skip to content

SYSTEM Cited by 4 sources

AWS KMS

AWS Key Management Service (KMS) is AWS's managed key-management service. It hosts customer keys (HSM-backed), exposes Wrap/Unwrap / Encrypt/Decrypt / Sign APIs under IAM, logs every operation to CloudTrail, and is the AWS endpoint of the Customer-Managed Key pattern for most AWS-hosted services.

Residency-aware recovery

Cryptographic-boundary recovery uses KMS as the controlled transition between an encrypted cross-Region copy and recoverable plaintext. A customer key policy can deny decryption in the recovery Region until an authorized recovery decision changes it. The source recommends limiting policy mutation to named principals/condition keys and optionally separating MFA approval from operational credentials; for client-side-encrypted S3 backups, multi-Region KMS keys can preserve the same key material across Regions. (Source: sources/2026-08-13-aws-recovery-strategies-to-meet-data-residency-requirements)

Seen in

Seen in

Last updated · 766 distilled / 2,225 read