Enterprise & Privacy

Data handling, privacy and governance in Kiro

Kiro from an Enterprise Perspective

Kiro is an AWS application. The AWS Shared Responsibility Model applies: AWS protects the infrastructure, organizations control their content. Enterprise users benefit from additional privacy guarantees compared to Free/Individual users.

🔒 Enterprise Benefits

  • No data retention by AWS
  • No foundation model training with enterprise data
  • Automatic opt-out from telemetry
  • Customer Managed Keys (CMK) for encryption
  • Centralized governance for models, MCP and API keys
  • SSO via IAM Identity Center, Okta or Microsoft Entra
  • IP Indemnity (liability protection for generated outputs)

🌍 Available Regions

  • US East (N. Virginia) — us-east-1
  • Europe (Frankfurt) — eu-central-1
  • AWS GovCloud (US) — us-gov-west-1

Data Flow – What Is Transmitted

When you interact with Kiro, the following data is sent to AWS:

  • Code context: Open files, file snippets, project structure (as needed for AI suggestions)
  • Chat messages: Your prompts and conversation history within a session
  • Telemetry: Usage metrics (Enterprise: opt-out by default)

Data is transmitted via TLS 1.2+ encrypted connections. Enterprise data is processed but not stored by AWS.

Encryption

Layer Method Details
In TransitTLS 1.2+All client-server communication
At Rest (default)AWS Owned KeysKMS managed by AWS
At Rest (Enterprise)Customer Managed KeysFull control over key lifecycle

Enterprise Governance

Enterprise admins control the following via the Kiro Console:

  • AI Models: Allowlist of permitted models per team/project
  • MCP Servers: Registry of approved servers and tools
  • API Keys: Centralized allocation and rotation
  • Web Tool Access: Enable/disable web search and fetch (default on)
  • Cloud Sessions: Controls Kiro Web, Agent Focus Mode and kiro-cli --cloud (default off for IAM Identity Center orgs)
  • Activity Reports: User activity and usage analytics

Policies are enforced deterministically in both IDE and CLI. Note: MCP config, model availability, and Customer Managed Keys do not apply to Kiro Web sessions.

Compliance

Standard Status
HIPAAEligible (IDE & CLI)
ISO/IEC 27001:2022Kiro in scope (verified by EY CertifyPoint)
AWS GovCloudConsole/Profile (US-East & US-West)
IP IndemnityPro / Pro+ / Power plans
GDPRCompliant with Enterprise + EU region

Frequently Asked Questions

Is enterprise data used for AI training?

No. AWS does not use enterprise content for service improvement or foundation model training. Enterprise users are automatically excluded from content collection and telemetry.

Where is Kiro data stored?

Enterprise users: no data retention by AWS. Free/Individual: US East (N. Virginia). Enterprise profiles can be configured in EU (Frankfurt) or AWS GovCloud.

What encryption does Kiro use?

TLS 1.2+ for data in transit. AWS Owned Keys by default for data at rest. Enterprise admins can configure Customer Managed Keys (CMK) for full control.

Is Kiro GDPR compliant?

Yes, with Enterprise subscription and EU region (Frankfurt). Enterprise data is not stored or used for training. A DPA with AWS is required.

What governance controls are available?

Admins control: allowed AI models, approved MCP servers, API key allocation, web tool access, and user activity reports via the Kiro Console.

What compliance certifications does Kiro have?

HIPAA Eligible (IDE & CLI) and ISO/IEC 27001:2022 for Kiro. AWS GovCloud available. AWS infrastructure audit reports via AWS Artifact. IP Indemnity for Pro/Pro+/Power plans.