I had the same question as you and took a look at their FQA.
#1 You should check what "HSM" is, and will know the answer to your question :D.
#2 KMS offers client-side encryptions. So if you don't trust AWS for whatever reason, you can choose to encrypt at client-side too. :D
Comments
I had the same question as you and took a look at their FQA.
#1 You should check what "HSM" is, and will know the answer to your question :D. #2 KMS offers client-side encryptions. So if you don't trust AWS for whatever reason, you can choose to encrypt at client-side too. :D