← Back to all announcements
★★★☆☆ 01/06/2026

Quick Research now supports customer managed keys

Bring your own KMS keys to Quick Research for full encryption control, 15-minute key revocation, and audit-ready CloudTrail logging.

View original announcement →

Visual Summary

graph TD A{{Quick Research CMK Support}}:::announced B(AWS KMS):::compute C(AWS CloudTrail):::compute D(Amazon Quick Research):::compute E([Encryption Control]):::feature F([Rapid Key Revocation]):::feature G([Audit Trail]):::feature H((Security Admin)):::external H ==>|"creates CMK"| B B ==>|"encrypts data"| A A -->|"protects"| D A -->|"logs events"| C A -->|"enables"| E A -.->|"within 15 min"| F C -->|"provides"| G classDef announced fill:#ff9900,stroke:#ec7211,color:#fff,font-weight:bold classDef compute fill:#e3f2fd,stroke:#1565c0,color:#1565c0 classDef storage fill:#e8f5e9,stroke:#2e7d32,color:#2e7d32 classDef feature fill:#fff3e0,stroke:#e65100,color:#e65100 classDef external fill:#f5f5f5,stroke:#616161,color:#616161

What's New

Amazon Quick Research now supports customer-managed keys (CMK) via AWS Key Management Service (KMS), giving organizations direct control over the encryption keys protecting their business intelligence and research data. This enhancement enables enterprises with strict security and compliance mandates to bring their own symmetric KMS keys rather than relying solely on AWS-managed encryption. The feature is generally available across all AWS Regions where Amazon Quick is supported.

How It Works

  • CMK Integration via AWS KMS: Customers create symmetric KMS keys in their own AWS account and region, then designate one as the default key per account per region for encrypting Quick Research data.
  • Symmetric Keys Only: Only symmetric AWS KMS keys are supported; asymmetric keys are not compatible with this feature.
  • Same-Account/Region Requirement: CMKs must reside in the same AWS account and region as the Quick Research resources they protect, preventing cross-account or cross-region key references.
  • Multiple CMK Support: Organizations can configure multiple CMKs to encrypt different datasets independently, with one key designated as the default per account per region, enabling granular data segmentation.
  • CloudTrail Audit Integration: All KMS key usage events—including encryption, decryption, and access attempts—are automatically logged in AWS CloudTrail, providing a comprehensive, tamper-evident audit trail.
  • Rapid Key Revocation: In the event of a security incident, access to a compromised key can be revoked within 15 minutes, immediately blocking further data access tied to that key.

Why It's Important

  • Regulatory Compliance: Industries subject to HIPAA, PCI-DSS, FedRAMP, GDPR, and similar frameworks often require organizations to demonstrate full control over encryption key lifecycle, which CMKs directly satisfy.
  • Reduced Blast Radius During Incidents: The ability to revoke a compromised key within 15 minutes dramatically limits exposure windows compared to waiting for AWS-managed key rotation cycles.
  • Auditability and Non-Repudiation: CloudTrail integration means every data access event is traceable to a specific principal and timestamp, which is critical for forensic investigations and compliance audits.
  • Data Sovereignty: Organizations operating in regulated jurisdictions can ensure that encryption keys never leave their control, supporting data sovereignty and residency requirements.
  • Granular Access Control: Multiple CMK support allows security teams to enforce least-privilege access at the dataset level, isolating sensitive research projects from one another cryptographically.
  • Trust Boundary Clarity: CMKs allow organizations to independently verify that AWS cannot access their data without explicit key authorization, strengthening the shared responsibility model.

How It's Different

  • Customer Control vs. AWS-Managed Keys: Unlike the default AWS-managed encryption where AWS controls key rotation and lifecycle, CMKs give customers full authority over key creation, rotation, disabling, and deletion.
  • Proactive Incident Response: The 15-minute revocation capability is a concrete, operationally defined SLA for incident containment—something not available with AWS-managed keys, which cannot be independently revoked by customers.
  • Per-Dataset Key Segmentation: Support for multiple CMKs with a configurable default allows finer-grained cryptographic isolation across datasets, which is not possible with a single shared AWS-managed key.
  • Integrated Audit Trail: While AWS-managed key usage may be logged, CMK usage in CloudTrail is directly tied to the customer's own account events, making it easier to correlate with internal SIEM and compliance tooling.
  • Symmetric-Only Constraint: The feature deliberately restricts support to symmetric KMS keys, aligning with KMS best practices for envelope encryption and ensuring broad compatibility with Quick Research's data encryption architecture.

When to Prefer It

  • Regulated Industries: Use CMKs when operating in healthcare, financial services, government, or other sectors where compliance frameworks explicitly require customer-controlled encryption key management.
  • Zero-Trust Security Architectures: Adopt CMKs when your security posture demands that no third party—including the cloud provider—can access data without your explicit cryptographic authorization.
  • Multi-Tenant or Multi-Project Environments: Use multiple CMKs to cryptographically isolate research datasets belonging to different business units, clients, or sensitivity classifications within the same AWS account.
  • Incident Response Planning: Prefer CMKs when your security runbooks require the ability to immediately cut off data access for a specific dataset during a breach, without affecting other workloads.
  • Audit-Heavy Compliance Programs: Choose CMKs when your organization undergoes frequent third-party audits and needs to produce detailed, verifiable logs of all data access events tied to encryption operations.
  • Data Residency Requirements: Use CMKs when operating in regions with strict data sovereignty laws that require demonstrable proof that encryption keys are managed within a specific jurisdiction.

Availability

  • GA Status: Generally available as of June 1, 2026; this is not a preview or beta release.
  • Supported Regions: Available in all AWS Regions where Amazon Quick is currently supported, including US East (N. Virginia), US West (Oregon), Asia Pacific (Singapore, Mumbai, Seoul, Tokyo), Europe, and others listed in the Quick regions documentation.
  • Key Constraints: Only symmetric AWS KMS keys are supported; asymmetric keys are explicitly not compatible.
  • Account/Region Boundary: CMKs must be created in the same AWS account and region as the Quick Research resources; cross-account and cross-region key references are not supported.
  • Default Key Configuration: One default CMK per AWS account per region is supported, with the ability to configure additional CMKs for different datasets.
  • Pricing: KMS key usage incurs standard AWS KMS charges (per key per month and per API call); Quick Research pricing itself is unchanged and follows existing Quick pricing tiers.

Tags

Servicesquick
Typenew-featuresecurity
Conceptsdata-analytics
Use Casesenterprise
GeographyGlobal

Related Resources

AI Radar AWS

AWS AI/ML news — curated, researched, explained

An automated intelligence platform that curates, researches, and analyzes AWS AI/ML/GenAI announcements daily. Every report is backed by real research — the system reads linked blog posts and documentation to provide accurate, in-depth analysis.

How Each Report Is Generated

  1. Collection — Daily monitoring of the AWS "What's New" RSS feed
  2. Filtering — AI-powered relevance detection for AI/ML/GenAI topics
  3. Taxonomy Tagging — LLM-based classification across 6 dimensions
  4. Importance Scoring — Point-based system with tag bonuses (1-5 stars)
  5. Research Phase — Follows links to blog posts and documentation
  6. Report Generation — Claude Sonnet produces structured 6-section analysis
  7. Visual Summary — Claude Opus generates Mermaid diagrams for key items
  8. Publishing — Static website rebuilt and deployed via CloudFront

Features

  • Faceted filtering by service, type, concept, and more
  • Multi-dimensional taxonomy with 80+ tags across 6 dimensions
  • Geographic availability badges (Global, APJ, EMEA, AMER) with filtering
  • Timeline visualization of announcement volume
  • PDF export for offline reading
  • Mermaid visual summaries for key announcements
  • Daily automated updates — no manual curation
What makes this different: Each report involves a dedicated research phase where the system reads linked blog posts and AWS documentation pages. This produces analysis that goes beyond the original announcement text.

Technology

Built with Python, AWS Lambda, Amazon Bedrock (Claude Sonnet 4.6, Opus 4.6, Haiku 4.5), S3, CloudFront, WAF, EventBridge, and CDK.

Open Source

This project is open source. Fork it, customize it for your needs, and deploy your own instance.
📦 github.com/bbonik/ai-radar-aws

How Importance Scoring Works

Each announcement receives a point score based on multiple factors. The total score maps to a 1-5 star rating:

1★ < 2 pts 2★ ≥ 2 pts 3★ ≥ 3.5 pts 4★ ≥ 5 pts 5★ ≥ 6.5 pts

Point Breakdown

FactorPointsWhen
Core AI service (Bedrock, AgentCore, SageMaker AI)+4Service named in title
Key AI service (SageMaker, Kiro, QuickSight)+2Service named in title
Other AI-related service+1Default
Blog post link+3Link to aws.amazon.com/blogs/
GitHub samples link+2Link to github.com/aws*
Documentation link+1Link to docs.aws.amazon.com/
New model+1.5Tagged as "new-model"
New service+1Tagged as "new-service"
New feature+0.5Tagged as "new-feature"
Anthropic / OpenAI provider+2Provider explicitly mentioned
Instance / notebook announcement-2Hardware/capacity, not feature
Performance / pricing / security-0.5Incremental updates
Region expansion to APJ+1Expands to Asia Pacific
Region expansion (non-APJ only)-1.5Only expands to other regions

Geographic Relevance Badges

Each announcement card shows a small badge indicating whether the feature is available in your region:

🌐 Global Available in all regions
🌏 APJ Asia Pacific
🌍 EMEA Europe / Middle East / Africa
🌎 AMER Americas (US, Canada, South America)
No badge Geography unknown
How geography is detected: The system detects ALL geographies mentioned in each announcement. If the text mentions specific regions (Tokyo, Frankfurt, Oregon, etc.), the corresponding geography badges are shown. If it says "all regions" or is a new feature with no region specified, it gets the Global badge. Geography is also filterable — click a geo chip to see only announcements available in that region.