Skip to main content

How are the encryption keys protected?

Written by amaise Support

How are the encryption keys protected?

The cryptographic keys are managed exclusively in AWS KMS and are physically and logically separated from the protected data. AWS KMS is based on a hardened HSM backend with FIPS 140-3 Level 3 certification.

No employee has direct access to the keys — only authorized AWS service components can use them. In justified exceptional cases, access can be requested with explicit approval from the technical management.

Every use of a document key is logged via CloudTrail with the calling principal, action, and timestamp — multi-region, integrity-validated, KMS-encrypted, and tamper-protected — so each key operation is auditable end to end. Key-policy and alias changes, denied access attempts, and any use of a document key by a principal outside amaise's own systems raise an immediate alarm to our security team. Annual automatic rotation is enabled for all KMS keys. AWS credentials are rotated regularly per security policy, and IAM database tokens expire after 15 minutes.

Did this answer your question?