Key Management (KMS)

Cryptographic key storage.

Cloud-hosted key management. Create, rotate, and manage encryption keys. FIPS 140-2 validated. Envelope encryption.

KEY MANAGEMENT SERVICE (KMS)1. CLIENT WORKLOADS๐ŸŒWeb ApplicationReq: Encrypt/Decryptโš™๏ธBatch ProcessorReq: Encrypt/DecryptโšกEdge WorkersReq: Encrypt/DecryptAPI CALLS ๐Ÿ”2. KEK MANAGEMENTENVELOPE ENCRYPTION๐Ÿ”‘MASTER KEKWRAPSEncrypted DEKFIPS 140-2 L3eDEK3. DATA AT REST๐ŸชฃObject StorageS3 / GCS bucketsAES-256 Encrypted๐Ÿ”’๐Ÿ’พCloud SQLPostgreSQL DataAES-256 Encrypted๐Ÿ”’๐Ÿ’ฟBlock VolumesPersistent DisksAES-256 Encrypted๐Ÿ”’๐Ÿ”„Auto-Rotation (90d)CMEK Supported

140-2 L2

FIPS

Automatic

Rotation

Sym/Asym

Types

Built-in

Envelope

Keys, managed.

FIPS 140-2. Auto-rotation. BYOK.

FIPS 140-2

FIPS 140-2 Level 2 validated key storage.

Auto-rotation

Automatic key rotation with configurable schedules.

Envelope encryption

Encrypt data keys with master keys for scale.

Symmetric & asymmetric

AES-256, RSA-2048/4096, and ECDSA keys.

BYOK

Bring your own keys or use cloud-generated.

Audit trail

Every key access event logged and auditable.

Getting started

Launch your first instance in three steps. CLI, console, or API โ€” your choice.

Terminal
ur kms key create db-encrypt \
  --type=symmetric --algo=aes-256 \
  --rotation=90d

KMS patterns.

Database encryption and compliance.

Database encryption

Encrypt databases at rest with managed keys.

View tutorial

Suggested configuration

AES-256 ยท Auto-rotate ยท Envelope

Estimate your costs

Create detailed configurations to see exactly how much your architecture will cost. Pay for what you use, down to the second.

Configuration 1

Estimated: $125.00/mo

Key Management

Processing Volume

ops/mo

Add-ons

Compliance ReportsSOC 2, HIPAA, PCI-DSS reporting
Config 1 cost$125.00

Cost details

$125.00

FIPS 140-2 Level 3 validated HSM storage available.

Configuration 1
$125.00
5 Protected Resource(s)$5.00
Event Processing$100.00
30-day Log Retention$20.00

Works seamlessly with

IAM
HSM
Secrets
Audit
Storage
SIEM

Frequently asked questions

Keys, managed.

FIPS 140-2 validated. Auto-rotation. BYOK.