Zhivko Todorov
ALL CASE STUDIES

CASE 102 · LUSTRE · 2025

KMSMULTI-REGION KEYSS3 REPLICATIONENCRYPTION

Encrypted replication that doesn’t need cross-region role gymnastics.

A digital health platform replicated PHI buckets across regions with a cross-region trust dance that nobody fully trusted. Auditors had questions. We rebuilt the encryption on KMS multi-region keys so the same key material exists in both regions, eliminating the trust path.

INDUSTRY

Digital health

DOMAIN

SECURITY

DELIVERED

2025

STACK

KMS MULTI-REGION KEYS·S3 CROSS-REGION REPLICATION·CLOUDTRAIL·AUDIT MANAGER·CONFIG

RESULTS

What changed, by the numbers.

CROSS-REGION TRUST PATHS

−100%

ELIMINATED

AUDIT QUESTIONS

CLEARED

CRYPTOGRAPHIC EXPLANATION

REPLICATION LATENCY

< 15s

UNCHANGED

KEY MATERIAL EXPOSURE

NONE

AWS-MANAGED REPLICATION

HOW IT WENT

The legacy setup decrypted in the source region, sent the plaintext to the destination region, and re-encrypted there. Both regions held distinct keys; the trust path was a cross-account IAM role with `kms:Decrypt` on the source side. Auditors had asked, reasonably, how we knew that path was secure.

KMS Multi-Region Keys hold the same key material in multiple regions without exposing the material to the customer. S3 replication can use the destination-region replica directly, eliminating the decrypt-and-re-encrypt round trip. We migrated three buckets representing the highest-sensitivity workloads first.

Cross-region trust paths went to zero. Replication latency was unchanged. The auditor’s questions resolved on a single architectural diagram. The migration ran transparently — existing encrypted objects could still be decrypted because we kept the legacy keys live during the transition window.

READY WHEN YOU ARE

Let's get your AWS bill (and architecture) in order.

The discovery call is free. You walk away with at least one concrete idea — even if we never work together.

Or email directly →