Encryption Targets
Bank-held key-encryption key (KEK) registration. The bank creates a symmetric
AES-256 KMS key in its own AWS account and grants the platform runtime role
kms:GenerateDataKey, kms:Encrypt, and kms:Decrypt on it. The platform
records only the key ARN and wraps a fresh per-message data key under it; key
material never leaves the bank's account. Revoking the grant or disabling the
key immediately removes the platform's access to that bank's stored messages.
The first KEK is registered during onboarding; this family covers replacement
afterwards.
Replace the key-encryption key
Registers a different key-encryption key (KEK) for this purpose after onboarding.