> For the complete documentation index, see [llms.txt](https://karansingh.gitbook.io/tutorialsdojo-wrong-answers-aws-sec-spec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://karansingh.gitbook.io/tutorialsdojo-wrong-answers-aws-sec-spec/s3-server-side-encryption.md).

# S3 Server-side Encryption

* **SSE-S3** requires that **S3 manages the data and the encryption keys:**
  * **Encrypts the key itself with a master key** that it regularly rotates.
  * **Uses** one of the strongest block ciphers available, **AES-256, to encrypt your data**.<br>
* **SSE-C** requires that **the customer manages the encryption keys**.<br>
* **SSE-KMS** requires that **AWS manages the data key but the customer manages the CMK in KMS**.
