DataTerrain Logo DataTerrain Logo DataTerrain Logo
  • Home
  • Why DataTerrain
  • Reports Conversion
  • Talent Acquisition
  • Services
    • ETL SolutionsETL Solutions
    • Performed multiple ETL pipeline building and integrations.

    • Oracle HCM Cloud Service MenuOracle HCM Analytics
    • 9 years of building Oracle HCM fusion analytics & reporting experience.

    • Data Lake IconData Lake
    • Experienced in building Data Lakes with Billions of records.

    • BI Products MenuBI products
    • Successfully delivered multiple BI product-based projects.

    • Legacy Scripts MenuLegacy scripts
    • Successfully transitioned legacy scripts from Mainframes to Cloud.

    • AI/ML Solutions MenuAI ML Consulting
    • Expertise in building innovative AI/ML-based projects.

  • Resources
    • Oracle HCM Tool
      Tools
    • Designed to facilitate data analysis and reporting processes.

    • HCM Cloud Analytics
      Latest News
    • Explore the Latest Tech News and Innovations Today.

    • Oracle HCM Cloud reporting tools
      Blogs
    • Practical articles with Proven Productivity Tips.

    • Oracle HCM Cloud reporting
      Videos
    • Watch the engaging and Informative Video Resources.

    • HCM Reporting tool
      Customer Stories
    • A journey that begins with your goals and ends with great outcomes.

    • Oracle Analytics tool
      Careers
    • Your career is a journey. Cherish the journey, and celebrate the wins.

  • Contact Us
  • Blogs
  • BI Insights Hub
  • Encryption of Data in Amazon QuickSight
  • 14 May 2025

Encryption of Data in Amazon QuickSight | SPICE, SSL & AWS KMS Security Explained

Understanding How Amazon QuickSight Encrypts Data at Rest and in Transit

Amazon QuickSight protects sensitive information through multiple encryption layers throughout its infrastructure. This includes encryption of data during transfer and at rest within the SPICE engine, secured by Amazon's security framework and AWS Key Management Service (KMS).

QuickSight encrypts data in transit and at rest using SSL, SPICE, and AWS Key Management Service (KMS), with optional support for Customer Master Key (CMK).
encryption-of-data-in-amazon-quicksight
  • Share Post:
  • LinkedIn Icon
  • Twitter Icon

1. Encryption During Data Transfers

All communication between data sources, Amazon QuickSight, SPICE, and the user interface is protected using Secure Socket Layer (SSL). SSL ensures that data in transit remains confidential and intact. You can configure SSL requirements when connecting QuickSight to external data sources. If encryption is not required, this option can be disabled based on security posture.

2. Encryption Within SPICE (Data at Rest)

Data imported into SPICE (Super-fast, Parallel, In-memory Calculation Engine) is encrypted at rest using keys managed by AWS Key Management Service (KMS). This secures stored dashboards, datasets, and analyses from unauthorized access. AWS automatically handles key rotation and storage security through KMS-managed keys unless customer-managed keys (CMKs) are specified.

3. Key Management Responsibilities

  • By default, AWS manages encryption keys for QuickSight.
  • If your environment uses self-signed or custom certificates, you are responsible for ensuring that a trusted Certificate Authority issues them.
  • Customers who require greater control can implement customer-managed KMS keys to comply with internal or regulatory encryption policies.

4. Data Visibility Controls QuickSight handles user metadata securely

  • Admins can only view usernames and email addresses.
  • Passwords remain private, encrypted, and inaccessible—even to administrators.

5. Recommendations for Security Best Practices

  • Consistently apply SSL for data source connections.
  • Implement customer-managed KMS keys when compliance or internal policy requires key control.
  • Regularly audit IAM policies to limit access to unnecessary data and resources.

About DataTerrain has supported over 300 U.S.-based clients with business intelligence tools, including Amazon QuickSight. Our flexible model offers scalable, expert-led engagements with no long-term commitments.

Categories
  • All
  • BI Insights Hub
  • Data Analytics
  • ETL Tools
  • Oracle HCM Insights
  • Legacy Reports conversion
  • AI and ML Hub

Ready to initiate your BI Migration Journey?

Start Now
Customer Stories
  • All
  • Data Analytics
  • Reports conversion
  • Jaspersoft
  • Oracle HCM
Recent posts
  • encryption-of-data-in-amazon-quicksight
    Encryption of Data in Amazon QuickSight...
  • cognos-analysis-studio
    Comprehensive Comparison: Cognos...
  • amazon-quicksight
    Row Level Security in Amazon QuickSight...
  • odbc-data-source-in-tableau
    Configuring XML as an ODBC data source for...
  • integration-services-etl-solutions
    Top Benefits of Using Integration Services ETL...
  • oracle-data-integrator-vs-informatica
    Oracle Data Integrator vs Informatica...
  • obiee-etl-tool-for-data-transformation
    OBIEE ETL Tool for Data Transformation...
  • how-to-secure-shared-folders-in-amazon-quicksight
    Understanding Shared Folder Security...
  • supported-and-unsupported-data-values-in-amazon-quicksight
    Supported & Unsupported Data Values...
  • jaspersoft-sub-reports
    Creating Effective JasperSoft Subreports...
  • integration-services-etl
    What is SQL Server Integration Services ETL...
Connect with Us
  • About
  • Careers
  • Privacy Policy
  • Terms and condtions
Sources
  • Customer stories
  • Blogs
  • Tools
  • News
  • Videos
  • Events
Services
  • Reports Conversion
  • ETL Solutions
  • Data Lake
  • Legacy Scripts
  • Oracle HCM Analytics
  • BI Products
  • AI ML Consulting
  • Data Analytics
Get in touch
  • connect@dataterrain.com
  • +1 650-701-1100

Subscribe to newsletter

Enter your email address for receiving valuable newsletters.

logo

© 2025 Copyright by DataTerrain Inc.

  • twitter