FEATURES / Encryption
/// Encryption
Encrypted at rest. On a key you control.
AWS already encrypts every bucket with SSE-S3 (AES-256). Storafleet lets you switch AWS buckets to SSE-KMS using your own KMS key — so you own rotation and get a CloudTrail decrypt audit trail — and shows the at-rest encryption status of every bucket across R2, B2, Wasabi, DigitalOcean, and MinIO.
Start for free/// How it works
See the encryption status of every bucket
Storafleet reads each bucket's default encryption configuration and shows it plainly. AWS buckets show SSE-S3 (AES-256) or SSE-KMS; R2, B2, Wasabi, and DigitalOcean show their at-rest status; MinIO and custom endpoints reflect the server's KMS config.
Switch an AWS bucket to your own KMS key
For AWS buckets, change default encryption from SSE-S3 to SSE-KMS and select one of your AWS KMS keys. Optionally turn on S3 Bucket Key to cut KMS request costs. This management is AWS-only — other providers are displayed, not changed.
Get rotation control and an audit trail
Once a bucket uses SSE-KMS, you own key rotation through KMS and every decrypt is logged to CloudTrail. Default encryption applies to newly uploaded objects — existing objects keep the encryption they were stored with.
Encrypted at rest by default — confirmed, not assumed
AWS already encrypts every bucket with SSE-S3 (AES-256). R2, B2, Wasabi, and DigitalOcean encrypt at rest by default too. Storafleet surfaces each bucket's actual status so you can prove it instead of taking it on faith.
Bring your own AWS KMS key
Switch any AWS bucket from SSE-S3 to SSE-KMS backed by a KMS key you own and control. The key lives in your AWS account — Storafleet never holds it. This is how you meet 'customer-managed keys' requirements without leaving the dashboard.
Own your key rotation
With SSE-KMS you control rotation policy on your own KMS key — enable automatic annual rotation or rotate on your own schedule. SSE-S3's keys are managed entirely by AWS, with no rotation policy you can set.
CloudTrail decrypt audit trail
Every decrypt against a SSE-KMS key is recorded in CloudTrail — who decrypted what, and when. That's the access record auditors ask for and that plain SSE-S3 cannot give you.
S3 Bucket Key to control KMS cost
SSE-KMS adds a KMS request per object operation. Enable the optional S3 Bucket Key from Storafleet and S3 generates a bucket-level data key, sharply reducing the number of KMS calls — and the bill — on high-traffic buckets.
Encrypted credentials, as defense-in-depth
Separate from bucket SSE: the storage credentials you give Storafleet are never stored in plaintext. Each is encrypted with a per-user AES-256-GCM key derived via HKDF, so a database leak alone never exposes your provider keys.
/// Without Storafleet
Your buckets are encrypted at rest, but you can't easily prove it, you don't control the keys, and there's no record of who decrypted what. Changing encryption means digging through each provider's console one account at a time.
- SSE-S3 keys are owned and rotated entirely by AWS — no policy you can set or point an auditor to
- No decrypt access trail with default SSE-S3 — you can't show who read the data
- Encryption status is buried in per-bucket settings, one console per provider
- Enabling SSE-KMS means the AWS Console or aws s3api put-bucket-encryption with the right key ARN
- S3 Bucket Key cost optimization is an easy-to-miss checkbox most people never enable
/// With Storafleet
Every bucket's at-rest status on one screen. For AWS, switch to your own KMS key in a click — with rotation control and a CloudTrail audit trail behind it.
- Switch AWS buckets to SSE-KMS with a KMS key you own — rotation policy is yours to set
- Every decrypt against the KMS key is logged to CloudTrail for the audit record
- At-rest encryption status for AWS, R2, B2, Wasabi, DigitalOcean, and MinIO in one view
- Switch SSE-S3 to SSE-KMS and back from the dashboard — no Console, no CLI, no key ARN to copy
- Enable S3 Bucket Key in the same step to cut KMS request costs on busy buckets
/// When you'll use this
Meeting a 'customer-managed keys' requirement
A new contract says data at rest must be encrypted with keys your company controls — SSE-S3, where AWS owns the keys, doesn't satisfy it. You open Storafleet, pick the bucket, switch default encryption to SSE-KMS, and select your own KMS key. Newly uploaded objects are now encrypted under a key you control, and you can point to it in the audit.
Key featureSwitch AWS buckets to SSE-KMS with a customer-managed key
Proving who decrypted production data
An auditor wants evidence of key rotation and a record of access. The bucket already uses SSE-KMS via Storafleet, so you enable annual rotation on the KMS key and pull the CloudTrail log of every decrypt event. Rotation policy and access trail, both on a key you own — exactly what SSE-S3 couldn't provide.
Key featureKey rotation control plus a CloudTrail decrypt audit trail
Confirming encryption across a multi-cloud estate
You run buckets on AWS, Cloudflare R2, Backblaze B2, and a self-hosted MinIO, and someone asks: is everything encrypted at rest? Instead of logging into four consoles, you open Storafleet and read the at-rest encryption status of every bucket on one screen — AWS keys included, MinIO reflecting its server KMS config.
Key featureAt-rest encryption status displayed across every provider
Your storage estate deserves a control plane.
Join the DevOps teams and founders who run every cloud's buckets from one control plane.
Free plan · No credit card · 50+ cloud providers · Cancel any time