Quick Research now supports customer managed keys
Bring your own KMS keys to Quick Research for full encryption control, 15-minute key revocation, and audit-ready CloudTrail logging.
View original announcement →Visual Summary
What's New
Amazon Quick Research now supports customer-managed keys (CMK) via AWS Key Management Service (KMS), giving organizations direct control over the encryption keys protecting their business intelligence and research data. This enhancement enables enterprises with strict security and compliance mandates to bring their own symmetric KMS keys rather than relying solely on AWS-managed encryption. The feature is generally available across all AWS Regions where Amazon Quick is supported.
How It Works
- CMK Integration via AWS KMS: Customers create symmetric KMS keys in their own AWS account and region, then designate one as the default key per account per region for encrypting Quick Research data.
- Symmetric Keys Only: Only symmetric AWS KMS keys are supported; asymmetric keys are not compatible with this feature.
- Same-Account/Region Requirement: CMKs must reside in the same AWS account and region as the Quick Research resources they protect, preventing cross-account or cross-region key references.
- Multiple CMK Support: Organizations can configure multiple CMKs to encrypt different datasets independently, with one key designated as the default per account per region, enabling granular data segmentation.
- CloudTrail Audit Integration: All KMS key usage events—including encryption, decryption, and access attempts—are automatically logged in AWS CloudTrail, providing a comprehensive, tamper-evident audit trail.
- Rapid Key Revocation: In the event of a security incident, access to a compromised key can be revoked within 15 minutes, immediately blocking further data access tied to that key.
Why It's Important
- Regulatory Compliance: Industries subject to HIPAA, PCI-DSS, FedRAMP, GDPR, and similar frameworks often require organizations to demonstrate full control over encryption key lifecycle, which CMKs directly satisfy.
- Reduced Blast Radius During Incidents: The ability to revoke a compromised key within 15 minutes dramatically limits exposure windows compared to waiting for AWS-managed key rotation cycles.
- Auditability and Non-Repudiation: CloudTrail integration means every data access event is traceable to a specific principal and timestamp, which is critical for forensic investigations and compliance audits.
- Data Sovereignty: Organizations operating in regulated jurisdictions can ensure that encryption keys never leave their control, supporting data sovereignty and residency requirements.
- Granular Access Control: Multiple CMK support allows security teams to enforce least-privilege access at the dataset level, isolating sensitive research projects from one another cryptographically.
- Trust Boundary Clarity: CMKs allow organizations to independently verify that AWS cannot access their data without explicit key authorization, strengthening the shared responsibility model.
How It's Different
- Customer Control vs. AWS-Managed Keys: Unlike the default AWS-managed encryption where AWS controls key rotation and lifecycle, CMKs give customers full authority over key creation, rotation, disabling, and deletion.
- Proactive Incident Response: The 15-minute revocation capability is a concrete, operationally defined SLA for incident containment—something not available with AWS-managed keys, which cannot be independently revoked by customers.
- Per-Dataset Key Segmentation: Support for multiple CMKs with a configurable default allows finer-grained cryptographic isolation across datasets, which is not possible with a single shared AWS-managed key.
- Integrated Audit Trail: While AWS-managed key usage may be logged, CMK usage in CloudTrail is directly tied to the customer's own account events, making it easier to correlate with internal SIEM and compliance tooling.
- Symmetric-Only Constraint: The feature deliberately restricts support to symmetric KMS keys, aligning with KMS best practices for envelope encryption and ensuring broad compatibility with Quick Research's data encryption architecture.
When to Prefer It
- Regulated Industries: Use CMKs when operating in healthcare, financial services, government, or other sectors where compliance frameworks explicitly require customer-controlled encryption key management.
- Zero-Trust Security Architectures: Adopt CMKs when your security posture demands that no third party—including the cloud provider—can access data without your explicit cryptographic authorization.
- Multi-Tenant or Multi-Project Environments: Use multiple CMKs to cryptographically isolate research datasets belonging to different business units, clients, or sensitivity classifications within the same AWS account.
- Incident Response Planning: Prefer CMKs when your security runbooks require the ability to immediately cut off data access for a specific dataset during a breach, without affecting other workloads.
- Audit-Heavy Compliance Programs: Choose CMKs when your organization undergoes frequent third-party audits and needs to produce detailed, verifiable logs of all data access events tied to encryption operations.
- Data Residency Requirements: Use CMKs when operating in regions with strict data sovereignty laws that require demonstrable proof that encryption keys are managed within a specific jurisdiction.
Availability
- GA Status: Generally available as of June 1, 2026; this is not a preview or beta release.
- Supported Regions: Available in all AWS Regions where Amazon Quick is currently supported, including US East (N. Virginia), US West (Oregon), Asia Pacific (Singapore, Mumbai, Seoul, Tokyo), Europe, and others listed in the Quick regions documentation.
- Key Constraints: Only symmetric AWS KMS keys are supported; asymmetric keys are explicitly not compatible.
- Account/Region Boundary: CMKs must be created in the same AWS account and region as the Quick Research resources; cross-account and cross-region key references are not supported.
- Default Key Configuration: One default CMK per AWS account per region is supported, with the ability to configure additional CMKs for different datasets.
- Pricing: KMS key usage incurs standard AWS KMS charges (per key per month and per API call); Quick Research pricing itself is unchanged and follows existing Quick pricing tiers.