Crusoe Cloud beefs up AI security

Crusoe Cloud rolls out Customer-Managed Keys (CMEK) for AWS KMS, giving enterprises direct control over their AI data encryption keys.

10 min read
Crusoe Cloud logo and text indicating Customer-Managed Keys for AWS KMS feature.

Visual TL;DR. AI Data Security Concerns drives Crusoe Cloud CMEK. Crusoe Cloud CMEK enables Direct Key Control. Direct Key Control leads to Enhanced Compliance. Direct Key Control provides Granular Control. Direct Key Control means Master Key Stays. Direct Key Control allows Revoke Access Fast. Enhanced Compliance contributes to Secure AI Workloads.

  1. AI Data Security Concerns: enterprises demand greater control over sensitive AI model and dataset encryption
  2. Crusoe Cloud CMEK: rolls out Customer-Managed Keys for AWS KMS on August 11, 2026
  3. Direct Key Control: customers manage their encryption keys directly within their own AWS accounts
  4. Enhanced Compliance: meets critical requirements for many regulated industries and security teams
  5. Granular Control: adds a significant layer of control beyond default data-at-rest encryption
  6. Master Key Stays: ensures the master encryption key remains within the customer's AWS environment
  7. Revoke Access Fast: allows quick revocation of access to encryption keys when needed
  8. Secure AI Workloads: beefs up security posture for AI and infrastructure workloads in production
Visual TL;DR
Visual TL;DR, startuphub.ai AI Data Security Concerns drives Crusoe Cloud CMEK. Crusoe Cloud CMEK enables Direct Key Control. Direct Key Control leads to Enhanced Compliance. Enhanced Compliance contributes to Secure AI Workloads drives enables leads to contributes to AI Data Security Concerns Crusoe Cloud CMEK Direct Key Control Enhanced Compliance Secure AI Workloads From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai AI Data Security Concerns drives Crusoe Cloud CMEK. Crusoe Cloud CMEK enables Direct Key Control. Direct Key Control leads to Enhanced Compliance. Enhanced Compliance contributes to Secure AI Workloads drives enables leads to contributes to AI Data SecurityConcerns Crusoe Cloud CMEK Direct KeyControl EnhancedCompliance Secure AIWorkloads From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai AI Data Security Concerns drives Crusoe Cloud CMEK. Crusoe Cloud CMEK enables Direct Key Control. Direct Key Control leads to Enhanced Compliance. Enhanced Compliance contributes to Secure AI Workloads drives enables leads to contributes to AI Data Security Concerns enterprises demand greater control oversensitive AI model and dataset encryption Crusoe Cloud CMEK rolls out Customer-Managed Keys for AWSKMS on August 11, 2026 Direct Key Control customers manage their encryption keysdirectly within their own AWS accounts Enhanced Compliance meets critical requirements for manyregulated industries and security teams Secure AI Workloads beefs up security posture for AI andinfrastructure workloads in production From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai AI Data Security Concerns drives Crusoe Cloud CMEK. Crusoe Cloud CMEK enables Direct Key Control. Direct Key Control leads to Enhanced Compliance. Enhanced Compliance contributes to Secure AI Workloads drives enables leads to contributes to AI Data SecurityConcerns enterprises demandgreater controlover sensitive AI… Crusoe Cloud CMEK rolls outCustomer-ManagedKeys for AWS KMS on… Direct KeyControl customers managetheir encryptionkeys directly… EnhancedCompliance meets criticalrequirements formany regulated… Secure AIWorkloads beefs up securityposture for AI andinfrastructure… From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai AI Data Security Concerns drives Crusoe Cloud CMEK. Crusoe Cloud CMEK enables Direct Key Control. Direct Key Control leads to Enhanced Compliance. Direct Key Control provides Granular Control. Direct Key Control means Master Key Stays. Direct Key Control allows Revoke Access Fast. Enhanced Compliance contributes to Secure AI Workloads drives enables leads to provides means allows contributes to AI Data Security Concerns enterprises demand greater control oversensitive AI model and dataset encryption Crusoe Cloud CMEK rolls out Customer-Managed Keys for AWSKMS on August 11, 2026 Direct Key Control customers manage their encryption keysdirectly within their own AWS accounts Enhanced Compliance meets critical requirements for manyregulated industries and security teams Granular Control adds a significant layer of control beyonddefault data-at-rest encryption Master Key Stays ensures the master encryption key remainswithin the customer's AWS environment Revoke Access Fast allows quick revocation of access toencryption keys when needed Secure AI Workloads beefs up security posture for AI andinfrastructure workloads in production From startuphub.ai · The publishers behind this format
Visual TL;DR, startuphub.ai AI Data Security Concerns drives Crusoe Cloud CMEK. Crusoe Cloud CMEK enables Direct Key Control. Direct Key Control leads to Enhanced Compliance. Direct Key Control provides Granular Control. Direct Key Control means Master Key Stays. Direct Key Control allows Revoke Access Fast. Enhanced Compliance contributes to Secure AI Workloads drives enables leads to provides means allows contributes to AI Data SecurityConcerns enterprises demandgreater controlover sensitive AI… Crusoe Cloud CMEK rolls outCustomer-ManagedKeys for AWS KMS on… Direct KeyControl customers managetheir encryptionkeys directly… EnhancedCompliance meets criticalrequirements formany regulated… Granular Control adds a significantlayer of controlbeyond default… Master Key Stays ensures the masterencryption keyremains within the… Revoke AccessFast allows quickrevocation ofaccess to… Secure AIWorkloads beefs up securityposture for AI andinfrastructure… From startuphub.ai · The publishers behind this format

Crusoe Cloud is enhancing its security posture for AI and infrastructure workloads with the introduction of Customer-Managed Keys (CMEK) for AWS Key Management Service (KMS). Announced on August 11, 2026, this move addresses growing enterprise demands for greater control over data encryption, particularly as sensitive AI models and datasets move into production environments. The new feature, detailed on the Crusoe Blog, allows customers to manage their encryption keys directly within their own AWS accounts, a critical requirement for many regulated industries.

As AI adoption accelerates, security and compliance teams are scrutinizing data protection measures. Key questions revolve around who controls encryption keys, who can access them, and how quickly that access can be revoked. While Crusoe Cloud already provides default data-at-rest encryption, CMEK adds a significant layer of granular control. It ensures that the master encryption key remains within the customer's AWS environment, with Crusoe Cloud receiving only scoped, temporary permissions to use it for decryption and encryption of data keys.

Why Direct Key Control Matters

Platform-managed encryption is standard, but enterprise-grade security often requires more. Organizations in heavily regulated sectors like finance or healthcare, or those handling highly sensitive intellectual property, need a clear separation of duties. They require keys to reside in their own cloud accounts, ensuring that the entity processing the data never holds the master key. The ability to revoke access instantly, without relying on vendor workflows, is also paramount. CMEK is designed precisely for these scenarios, offering the security benefits of independent key management without sacrificing the managed experience of Crusoe Cloud.

This development aligns with a broader trend in cloud security where customers are increasingly demanding more transparency and control over their data. Similar offerings exist for other cloud platforms, such as Databricks’ customer key control for Postgres, indicating a market-wide push towards empowering users with direct management of their encryption keys, especially for critical data infrastructure.

How Crusoe's CMEK Works

The implementation of CMEK for AWS KMS on Crusoe Cloud centers around an AWS Identity and Access Management (IAM) role that the customer creates and manages. This role is configured to trust Crusoe Cloud’s specific IAM role, with the customer’s Crusoe project ID acting as an ExternalId to isolate access. Permissions granted include the ability to call KMS actions such as Encrypt, Decrypt, GenerateDataKey, and ReEncrypt* (though only Encrypt and Decrypt are currently utilized by Crusoe, with others reserved for future capabilities like key rotation). By providing the ARNs for both the IAM role and the KMS key to Crusoe Cloud, customers initiate a validation process. Crusoe Cloud performs a test encrypt/decrypt operation to confirm the setup before activating CMEK. This ensures that the master key never leaves the customer’s AWS account, and Crusoe Cloud only gains temporary, permission-bound access.

This approach adheres to the standard envelope encryption pattern. Crusoe encrypts data using a unique data key, and then uses the customer’s KMS key solely to encrypt and decrypt that data key. This method means the customer’s KMS key is only ever used for the small data keys, not the bulk data itself, which is why the permissions are scoped to Encrypt and Decrypt. Furthermore, AWS KMS handles key rotation automatically, embedding the key version within the ciphertext, so Crusoe Cloud transparently accommodates these rotations without customer intervention.

Security and Compliance Benefits

The introduction of CMEK provides tangible benefits for security and compliance teams. It establishes a clear segregation of duties: Crusoe Cloud handles data processing and storage, while the customer retains full ownership and control of the encryption keys in their AWS KMS. This separation is a key control point that organizations can map to compliance frameworks like SOC 2, HIPAA, or PCI-DSS. The ability to revoke access is immediate; by disabling the IAM role or modifying the KMS key policy on the customer’s AWS side, Crusoe Cloud loses its decryption capability instantly, without impacting the stored data itself. Audit trails are also enhanced, as all KMS calls made by Crusoe Cloud are logged in the customer’s AWS CloudTrail, with the session name clearly indicating the originating Crusoe project ID.

Crusoe Cloud, which holds a StartupHub score of 65/100 and has VERIFIED financials: raised $3B (Funding Round, 2026), competes in a crowded AI infrastructure market. Competitors like Memories.ai (score 52/100) and Bridgepointe Technologies (score 63/100) also focus on enterprise solutions, but Crusoe’s emphasis on specialized AI infrastructure, including its GPU offerings with NVIDIA and AMD hardware, positions it uniquely. The addition of CMEK targets a specific pain point for large enterprises that cannot compromise on data sovereignty and control, a segment where AI infrastructure investments are seeing significant traction.

Getting Started with CMEK

The setup process for CMEK is designed to be straightforward, involving three main steps accessible via the AWS Console or AWS CLI. First, customers select or create a symmetric KMS key with Encrypt/Decrypt capabilities in their desired region. Second, they create an IAM role in their AWS account that trusts Crusoe Cloud’s specific role and includes an inline policy granting the necessary KMS permissions. Finally, they register the key and role ARNs within the Crusoe portal. Crusoe Cloud validates the configuration before activation, ensuring a secure and correct setup.

This feature is available now for Crusoe Cloud customers. The company encourages users to reach out to their account teams for assistance with setup and integration into their compliance strategies.

© 2026 StartupHub.ai. All rights reserved. Do not enter, scrape, copy, reproduce, or republish this article in whole or in part. Use as input to AI training, fine-tuning, retrieval-augmented generation, or any machine-learning system is prohibited without written license. Substantially-similar derivative works will be pursued to the fullest extent of applicable copyright, database, and computer-misuse laws. See our terms.