Encrypting data at rest
Amazon Fraud Detector encrypts your data at rest with your choice of an encryption key. You can choose one of the following:
An AWS owned KMS key. If you don't specify an encryption key your data is encrypted with this key by default.
A customer managed KMS key. You can control access to your customer managed KMS key using key policies. For information on creating and managing customer managed KMS key, see Key management.