Back

Product

KMS-managed keys for column encryption

Column encryption supports AWS KMS-managed keys through encryptionKMSConfig, and existing plaintext passphrase configurations keep working unchanged.

Column encryption previously required a plaintext passphrase in configuration. Customers who store their encryption passphrase in AWS KMS — as required by many security policies — could not use Artie's column encryption feature at all.

Column encryption now supports AWS KMS-managed keys via encryptionKMSConfig. The previous behavior (plaintext passphrase) continues to work unchanged.

Why this matters

  • Unblocks column encryption for teams with KMS-enforced security policies
  • No behavior change for existing plaintext-passphrase configurations
Column encryption docs