Amazon Cognito now supports customer managed keys in AWS Key Management Service (KMS) for encrypting user pool data at rest. While AWS owned keys are used by default to protect your data, customer managed keys give you full control over the encryption keys, helping you achieve your organization’s data governance objectives. With customer managed keys, you can define organizational policies and revoke access to encrypted data by disabling or deleting your key.