Crusoe Cloud beefs up AI security

Crusoe Cloud rolls out Customer-Managed Keys (CMEK) for AWS KMS, giving enterprises direct control over their AI data encryption keys.

Crusoe Cloud logo and text indicating Customer-Managed Keys for AWS KMS feature.
Visual TL;DR
AI Data Security ConcernsDriver
enterprises demand greater control over sensitive AI model and dataset encryption
From the article 2 mentionsAs AI adoption accelerates, security and compliance teams are scrutinizing data protection measures.
Crusoe Cloud CMEKCore
rolls out Customer-Managed Keys for AWS KMS on August 11, 2026
From the article 9+ mentionsCrusoe Cloud is enhancing its security posture for AI and infrastructure workloads with the introduction of Customer-Managed Keys (CMEK) for AWS Key Management Service (KMS).
Direct Key ControlEffect
customers manage their encryption keys directly within their own AWS accounts
From the article 3 mentionsSimilar offerings exist for other cloud platforms, such as Databricks’ customer key control for Postgres, indicating a market-wide push towards empowering users with direct management of their encryption keys, especially for critical data infrastructure.
Enhanced ComplianceOutcome
meets critical requirements for many regulated industries and security teams
From the article 5 mentionsAudit trails are also enhanced, as all KMS calls made by Crusoe Cloud are logged in the customer’s AWS CloudTrail, with the session name clearly indicating the originating Crusoe project ID.
Granular ControlEffect
From the article 8 mentionsWhile Crusoe Cloud already provides default data-at-rest encryption, CMEK adds a significant layer of granular control.
Master Key StaysContext
From the article 3 mentionsIt ensures that the master encryption key remains within the customer's AWS environment, with Crusoe Cloud receiving only scoped, temporary permissions to use it for decryption and encryption of data keys.
Revoke Access FastEffect
allows quick revocation of access to encryption keys when needed
From the article 2 mentionsThe ability to revoke access instantly, without relying on vendor workflows, is also paramount.
Secure AI WorkloadsOutcome
beefs up security posture for AI and infrastructure workloads in production
From the article 2 mentionsCrusoe Cloud validates the configuration before activation, ensuring a secure and correct setup.
Contents(4)

Crusoe Cloud is enhancing its security posture for AI and infrastructure workloads with the introduction of Customer-Managed Keys (CMEK) for AWS Key Management Service (KMS). Announced on August 11, 2026, this move addresses growing enterprise demands for greater control over data encryption, particularly as sensitive AI models and datasets move into production environments. The new feature, detailed on the Crusoe Blog, allows customers to manage their encryption keys directly within their own AWS accounts, a critical requirement for many regulated industries.

As AI adoption accelerates, security and compliance teams are scrutinizing data protection measures. Key questions revolve around who controls encryption keys, who can access them, and how quickly that access can be revoked. While Crusoe Cloud already provides default data-at-rest encryption, CMEK adds a significant layer of granular control. It ensures that the master encryption key remains within the customer's AWS environment, with Crusoe Cloud receiving only scoped, temporary permissions to use it for decryption and encryption of data keys.

Why Direct Key Control Matters

Platform-managed encryption is standard, but enterprise-grade security often requires more. Organizations in heavily regulated sectors like finance or healthcare, or those handling highly sensitive intellectual property, need a clear separation of duties. They require keys to reside in their own cloud accounts, ensuring that the entity processing the data never holds the master key. The ability to revoke access instantly, without relying on vendor workflows, is also paramount. CMEK is designed precisely for these scenarios, offering the security benefits of independent key management without sacrificing the managed experience of Crusoe Cloud.

This development aligns with a broader trend in cloud security where customers are increasingly demanding more transparency and control over their data. Similar offerings exist for other cloud platforms, such as Databricks’ customer key control for Postgres, indicating a market-wide push towards empowering users with direct management of their encryption keys, especially for critical data infrastructure.

How Crusoe's CMEK Works

The implementation of CMEK for AWS KMS on Crusoe Cloud centers around an AWS Identity and Access Management (IAM) role that the customer creates and manages. This role is configured to trust Crusoe Cloud’s specific IAM role, with the customer’s Crusoe project ID acting as an ExternalId to isolate access. Permissions granted include the ability to call KMS actions such as Encrypt, Decrypt, GenerateDataKey, and ReEncrypt* (though only Encrypt and Decrypt are currently utilized by Crusoe, with others reserved for future capabilities like key rotation). By providing the ARNs for both the IAM role and the KMS key to Crusoe Cloud, customers initiate a validation process. Crusoe Cloud performs a test encrypt/decrypt operation to confirm the setup before activating CMEK. This ensures that the master key never leaves the customer’s AWS account, and Crusoe Cloud only gains temporary, permission-bound access.

This approach adheres to the standard envelope encryption pattern. Crusoe encrypts data using a unique data key, and then uses the customer’s KMS key solely to encrypt and decrypt that data key. This method means the customer’s KMS key is only ever used for the small data keys, not the bulk data itself, which is why the permissions are scoped to Encrypt and Decrypt. Furthermore, AWS KMS handles key rotation automatically, embedding the key version within the ciphertext, so Crusoe Cloud transparently accommodates these rotations without customer intervention.

Security and Compliance Benefits

The introduction of CMEK provides tangible benefits for security and compliance teams. It establishes a clear segregation of duties: Crusoe Cloud handles data processing and storage, while the customer retains full ownership and control of the encryption keys in their AWS KMS. This separation is a key control point that organizations can map to compliance frameworks like SOC 2, HIPAA, or PCI-DSS. The ability to revoke access is immediate; by disabling the IAM role or modifying the KMS key policy on the customer’s AWS side, Crusoe Cloud loses its decryption capability instantly, without impacting the stored data itself. Audit trails are also enhanced, as all KMS calls made by Crusoe Cloud are logged in the customer’s AWS CloudTrail, with the session name clearly indicating the originating Crusoe project ID.

Crusoe Cloud, which holds a StartupHub score of 65/100 and has VERIFIED financials: raised $3B (Funding Round, 2026), competes in a crowded AI infrastructure market. Competitors like Memories.ai (score 52/100) and Bridgepointe Technologies (score 63/100) also focus on enterprise solutions, but Crusoe’s emphasis on specialized AI infrastructure, including its GPU offerings with NVIDIA and AMD hardware, positions it uniquely. The addition of CMEK targets a specific pain point for large enterprises that cannot compromise on data sovereignty and control, a segment where AI infrastructure investments are seeing significant traction.

Getting Started with CMEK

The setup process for CMEK is designed to be straightforward, involving three main steps accessible via the AWS Console or AWS CLI. First, customers select or create a symmetric KMS key with Encrypt/Decrypt capabilities in their desired region. Second, they create an IAM role in their AWS account that trusts Crusoe Cloud’s specific role and includes an inline policy granting the necessary KMS permissions. Finally, they register the key and role ARNs within the Crusoe portal. Crusoe Cloud validates the configuration before activation, ensuring a secure and correct setup.

This feature is available now for Crusoe Cloud customers. The company encourages users to reach out to their account teams for assistance with setup and integration into their compliance strategies.

© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Daniel Singer

Written by

Daniel Singer

Editor, StartupHub.ai

Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.