Glossary

    Server-Side Encryption (SSE)

    Data Protection

    Server-Side Encryption (SSE) means AWS encrypts your data after receiving it and decrypts it when you access it. The encryption/decryption is transparent to your application.

    S3 SSE Options

    • SSE-S3: AWS manages keys (default since Jan 2023)
    • SSE-KMS: KMS manages keys; you control policies and audit key usage
    • SSE-C: you provide the key with each request; AWS never stores it
    • DSSE-KMS: dual-layer encryption for compliance requirements

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.