AWS Payment Cryptography is designed so that no one, including AWS employees, can retrieve your plaintext payment keys from the service. AWS Payment Cryptography uses HSMs that have been validated under PCI PTS HSM to protect the confidentiality and integrity of your keys. Your plaintext payment keys never leave the HSMs, are never written to disk, and are only ever used in the volatile memory of the HSMs for the time needed to perform your requested cryptographic operation. Secure handling of HSMs for the service with dual control and integrity validation is maintained from manufacture through service integration, operation, and decommissioning. Service main keys can only be loaded onto these validated HSM within designated areas with AWS data centers. Updates to software on the service hosts and to the HSM firmware is controlled by multiparty access control that is audited and reviewed by an independent group within Amazon and a PCI-certified lab in compliance with PCI PTS HSM. All security, HSM management, and key management processes are regularly assessed by internal Amazon teams and third-party assessors.