Skip to main content

Encryption Targets

Bank-held key-encryption key (KEK) registration. The bank creates a symmetric AES-256 KMS key in its own AWS account and grants the platform runtime role kms:GenerateDataKey, kms:Encrypt, and kms:Decrypt on it. The platform records only the key ARN and wraps a fresh per-message data key under it; key material never leaves the bank's account. Revoking the grant or disabling the key immediately removes the platform's access to that bank's stored messages. The first KEK is registered during onboarding; this family covers replacement afterwards.