SageMaker MLflow now supports customer managed keys

SageMaker MLflow Updates
SageMaker MLflow now enables customers to encrypt their data using customer-managed keys (CMK) through AWS Key Management Service (KMS). This enhancement allows organizations with strict security and compliance requirements to manage their own encryption keys. With customer-managed keys, you gain enhanced security control and comprehensive audit capabilities through AWS CloudTrail integration.
Customer-managed keys must be created in the same AWS account and region as your MLflow App, and only symmetric AWS KMS keys are supported. This feature is generally available in all AWS Regions where MLflow App is available.
What to do
- Create symmetric AWS KMS keys in the same AWS account and region as your MLflow App.
- Configure your MLflow App to use these keys for data encryption.
- Monitor data access and encryption through AWS CloudTrail.
Source: AWS release notes
If you need further guidance on AWS, our experts are available at AWS@westloop.io. You may also reach us by submitting the Contact Us form.



