Does amaise support customer-owned encryption keys (BYOK/CMK)?
Yes. Each tenant in amaise receives a dedicated KMS key (Customer Managed Key) for encrypting their customer data in S3. The keys are of type SYMMETRIC_DEFAULT and are automatically rotated annually.
An internal compliance service monitors the entire lifecycle of the keys: it ensures that active tenants have an active CMK and that when a tenant is deleted, the associated key is properly decommissioned (with a 7-day deletion window).
For customers with special data sovereignty requirements, amaise offers complete cryptographic separation of tenant data. Upon request, a Bring-Your-Own-Key (BYOK) model can be supported — contact us at [email protected] for details.
