# Crusoe Cloud beefs up AI security _Crusoe Cloud rolls out Customer-Managed Keys (CMEK) for AWS KMS, giving enterprises direct control over their AI data encryption keys._ **Published:** 2026-08-11 **Source:** https://www.startuphub.ai/ai-news/ai/2026/crusoe-cloud-beefs-up-ai-security --- Crusoe Cloud is enhancing its security posture for AI and infrastructure workloads with the introduction of Customer-Managed Keys (CMEK) for AWS Key Management Service (KMS). Announced on August 11, 2026, this move addresses growing enterprise demands for greater control over data encryption, particularly as sensitive AI models and datasets move into production environments. The new feature, detailed on the [Crusoe Blog](https://www.crusoe.ai/resources/blog/customer-managed-keys-for-aws-kms-on-crusoe-cloud), allows customers to manage their encryption keys directly within their own AWS accounts, a critical requirement for many regulated industries. AI Data Security ConcernsDriver enterprises demand greater control over sensitive AI model and dataset encryptionFrom the article 2 mentionsAs AI adoption accelerates, security and compliance teams are scrutinizing data protection measures.drivesCrusoe Cloud CMEKCorerolls out Customer-Managed Keys for AWS KMS on August 11, 2026From the article 9+ mentionsCrusoe Cloud is enhancing its security posture for AI and infrastructure workloads with the introduction of Customer-Managed Keys (CMEK) for AWS Key Management Service (KMS).enablesDirect Key ControlEffectcustomers manage their encryption keys directly within their own AWS accountsFrom the article 3 mentionsSimilar offerings exist for other cloud platforms, such as Databricks’ customer key control for Postgres, indicating a market-wide push towards empowering users with direct management of their encryption keys, especially for critical data infrastructure.Enhanced ComplianceOutcomemeets critical requirements for many regulated industries and security teamsFrom the article 5 mentionsAudit trails are also enhanced, as all KMS calls made by Crusoe Cloud are logged in the customer’s AWS CloudTrail, with the session name clearly indicating the originating Crusoe project ID.Granular ControlEffectFrom the article 8 mentionsWhile Crusoe Cloud already provides default data-at-rest encryption, CMEK adds a significant layer of granular control.Master Key StaysContextFrom the article 3 mentionsIt ensures that the master encryption key remains within the customer's AWS environment, with Crusoe Cloud receiving only scoped, temporary permissions to use it for decryption and encryption of data keys.Revoke Access FastEffectallows quick revocation of access to encryption keys when neededFrom the article 2 mentionsThe ability to revoke access instantly, without relying on vendor workflows, is also paramount.Secure AI WorkloadsOutcomebeefs up security posture for AI and infrastructure workloads in productionFrom the article 2 mentionsCrusoe Cloud validates the configuration before activation, ensuring a secure and correct setup. As AI adoption accelerates, security and compliance teams are scrutinizing data protection measures. Key questions revolve around who controls encryption keys, who can access them, and how quickly that access can be revoked. While Crusoe Cloud already provides default data-at-rest encryption, CMEK adds a significant layer of granular control. It ensures that the master encryption key remains within the customer's AWS environment, with Crusoe Cloud receiving only scoped, temporary permissions to use it for decryption and encryption of data keys. ## Why Direct Key Control Matters Platform-managed encryption is standard, but enterprise-grade security often requires more. Organizations in heavily regulated sectors like finance or healthcare, or those handling highly sensitive intellectual property, need a clear separation of duties. They require keys to reside in their own cloud accounts, ensuring that the entity processing the data never holds the master key. The ability to revoke access instantly, without relying on vendor workflows, is also paramount. CMEK is designed precisely for these scenarios, offering the security benefits of independent key management without sacrificing the managed experience of Crusoe Cloud. This development aligns with a broader trend in cloud security where customers are increasingly demanding more transparency and control over their data. Similar offerings exist for other cloud platforms, such as [Databricks’ customer key control for Postgres](/ai-news/technology/2026/databricks-postgres-gets-customer-key-control), indicating a market-wide push towards empowering users with direct management of their encryption keys, especially for critical data infrastructure. ## How Crusoe's CMEK Works The implementation of CMEK for AWS KMS on Crusoe Cloud centers around an AWS Identity and Access Management (IAM) role that the customer creates and manages. This role is configured to trust Crusoe Cloud’s specific IAM role, with the customer’s Crusoe project ID acting as an ExternalId to isolate access. Permissions granted include the ability to call KMS actions such as Encrypt, Decrypt, GenerateDataKey, and ReEncrypt* (though only Encrypt and Decrypt are currently utilized by Crusoe, with others reserved for future capabilities like key rotation). By providing the ARNs for both the IAM role and the KMS key to Crusoe Cloud, customers initiate a validation process. Crusoe Cloud performs a test encrypt/decrypt operation to confirm the setup before activating CMEK. This ensures that the master key never leaves the customer’s AWS account, and Crusoe Cloud only gains temporary, permission-bound access. This approach adheres to the standard envelope encryption pattern. Crusoe encrypts data using a unique data key, and then uses the customer’s KMS key solely to encrypt and decrypt that data key. This method means the customer’s KMS key is only ever used for the small data keys, not the bulk data itself, which is why the permissions are scoped to Encrypt and Decrypt. Furthermore, AWS KMS handles key rotation automatically, embedding the key version within the ciphertext, so Crusoe Cloud transparently accommodates these rotations without customer intervention. ## Security and Compliance Benefits The introduction of CMEK provides tangible benefits for security and compliance teams. It establishes a clear segregation of duties: Crusoe Cloud handles data processing and storage, while the customer retains full ownership and control of the encryption keys in their AWS KMS. This separation is a key control point that organizations can map to compliance frameworks like SOC 2, HIPAA, or PCI-DSS. The ability to revoke access is immediate; by disabling the IAM role or modifying the KMS key policy on the customer’s AWS side, Crusoe Cloud loses its decryption capability instantly, without impacting the stored data itself. Audit trails are also enhanced, as all KMS calls made by Crusoe Cloud are logged in the customer’s AWS CloudTrail, with the session name clearly indicating the originating Crusoe project ID. Crusoe Cloud, which holds a [StartupHub score of 65/100](https://www.startup.ai/company/crusoe) and has [VERIFIED financials: raised $3B (Funding Round, 2026)](/ai-news/funding-round/2025/crusoe-ai-funding-1375b-to-build-ai-factories), competes in a crowded AI infrastructure market. Competitors like Memories.ai (score 52/100) and Bridgepointe Technologies (score 63/100) also focus on enterprise solutions, but Crusoe’s emphasis on specialized AI infrastructure, including its GPU offerings with NVIDIA and AMD hardware, positions it uniquely. The addition of CMEK targets a specific pain point for large enterprises that cannot compromise on data sovereignty and control, a segment where [AI infrastructure investments are seeing significant traction](/ai-news/ai-news/2026/ai-infrastructure-week-july-6-2026). ## Getting Started with CMEK The setup process for CMEK is designed to be straightforward, involving three main steps accessible via the AWS Console or AWS CLI. First, customers select or create a symmetric KMS key with Encrypt/Decrypt capabilities in their desired region. Second, they create an IAM role in their AWS account that trusts Crusoe Cloud’s specific role and includes an inline policy granting the necessary KMS permissions. Finally, they register the key and role ARNs within the Crusoe portal. Crusoe Cloud validates the configuration before activation, ensuring a secure and correct setup. This feature is available now for Crusoe Cloud customers. The company encourages users to reach out to their account teams for assistance with setup and integration into their compliance strategies. --- Original analysis from [startuphub.ai](https://www.startuphub.ai), the #1 AI startup directory.