Data protection - Privacy and Security - Docs - Kiro
https://kiro.dev/docs/privacy-and-security/data-protection/ • 233 KB fetched
Open original page
Data protection - Privacy and Security - Docs - Kiro
Loading image... Product
* About Kiro
* IDE
* CLI
* Web
* Mobile
* Crew
* Pricing
* Downloads
For
* Enterprise
* Startups
* Students
Community
* Overview
* Ambassadors
* Discord
* Events
* Powers
* Shop
* Showcase
Resources
* Docs
* Blog
* Changelog
* FAQs
* Report a bug
* Suggest an idea
* Billing support
Social
*
*
*
*
*
*
*
English
Site Terms License Responsible AI Policy Legal Privacy Policy Cookie Preferences English
Loading image...
* Apps
* CLI
* Web
* Enterprise
* Pricing
* Docs
* Community
* Resources
SIGN IN DOWNLOADS
Loading image...
Get Started
Installation Authentication Your first project
Models
Overview Available models Reasoning effort
Features
How Kiro works Specs
Steering Hooks
MCP
Permissions Custom agents
Agent Skills Powers
Cloud sessions Compaction Kiroignore Checkpoints and rewind Built-in tools
Configuration scopes
IDE 1.x
What's new in 1.0
Setup & First Run Editor
Chat
Experimental
Troubleshooting 0.x reference
CLI
What's new in 3.0
Setup & First Run Terminal UI
Chat
Voice mode Headless mode ACP Auto complete Experimental
2.x reference
Crew
Quick start Installation Running 24/7 Chat
Agent Capabilities
Features
Interfaces
Apps
System & storage Configuration Security Troubleshooting
Web
Setup & First Run Identity Center Connect your repositories
Working with the agent
Autonomous mode Automations Memory Configuration Sync Sandbox
Mobile - Preview
Overview
Commands and Reference
CLI commands Slash commands Built-in tools Exit codes Settings
Billing
Overview Managing your subscription Upgrading your plan Downgrading your plan Cancelling your plan Purchasing add-on credits Managing your payments Managing usage notifications Managing your taxes Contacting billing support Deleting your account Related questions
Enterprise
Concepts Onboarding quickstart Connecting your identity provider
Deployment options Subscribe your team Manage subscriptions Governance
Monitor and track
Settings Managed updates Billing IAM Supported regions
Privacy and Security
Overview Data protection Code references Compliance validation Infrastructure security IAM permissions Firewalls, proxies, and data perimeters VPC endpoints (AWS PrivateLink)
Guides
Overview Language support
Learn by playing
Migration
Migrating from Q Developer Migrating from VSCode Upgrading from Q CLI
* Docs
*
* Privacy and Security
*
* Data protection
Copy page View as Markdown
Data protection
Copy page View as Markdown
The AWS shared responsibility model applies to data protection in Kiro. As described in this model, AWS is responsible for protecting the global infrastructure that runs all of the AWS Cloud. You are responsible for maintaining control over your content that is hosted on this infrastructure. You are also responsible for the security configuration and management tasks for the AWS services that you use. For more information about data privacy, see the Data Privacy FAQ .
Data storage
Kiro stores your questions, responses, additional context such as code and metadata about your requests to generate new responses to your requests and in some circumstances for abuse detection purposes (for more information, see Abuse detection ). When you or your administrator enable prompt logging or daily usages report, we'll also store the data necessary to publish reports and log events. For information about how data is encrypted, see Data encryption . For information about how AWS may use some questions that you ask Kiro and its responses to improve our services, see Kiro service improvement .
AWS regions where content is stored and processed
If you are a Kiro Free Tier user or a Kiro individual subscriber, your content, such as prompts and responses, will be stored in the US East (N. Virginia) Region.
If you are a Kiro enterprise user , your content, such as prompts and responses, may be stored in the region where your profile is configured in order to provide and maintain the service (ex: prompt logging, daily activity report), but it will not be used for service improvement.
With cross-region inferencing, your content may be processed in a different Region within the geography where your content is stored. For more information, see Cross-region processing .
Cross-region processing
The following sections describe how cross-region inference and cross-region calls are used to provide the Kiro service.
Cross-region inference
Kiro is powered by Amazon Bedrock, and uses cross-region inference to distribute traffic across different AWS Regions to enhance large language model (LLM) inference performance and reliability. With cross-region inference, you get increased throughput and resilience during high demand periods, as well as improved performance.
Cross region inference doesn't affect where your data is stored. For information on where data is stored when you use Kiro, see AWS Regions where content is stored and processed .
Supported regions for Kiro cross-region inference
For models or capabilities under the experimental tag, see " Global cross-region inference for experimental features ".
Supported Kiro geography Inference regions
United States
* US East (N. Virginia) ( us-east-1 )
* US West (Oregon) ( us-west-2 )
* US East (Ohio) ( us-east-2 )
* AWS GovCloud (US-East)
* AWS GovCloud (US-West)
Europe
* Europe (Frankfurt) ( eu-central-1 )
* Europe (Ireland) ( eu-west-1 )
* Europe (Paris) ( eu-west-3 )
* Europe (Stockholm) ( eu-north-1 )
* Europe (Milan) ( eu-south-1 )
* Europe (Spain) ( eu-south-2 )
Global cross-region inference for experimental features
Kiro may introduce new models and capabilities under an experimental tag, which process data differently than in the table above. When a model is launched as experimental, Kiro may use global cross-region inference to improve performance, increase throughput, and take advantage of available capacity across supported commercial AWS Regions worldwide. Global cross-region inference applies only to models explicitly designated as experimental.
For models and capabilities marked as experimental:
* Inference requests may be processed in multiple AWS Regions globally, including Regions outside the one associated with your Kiro profile.
* The Region where your data is stored is not affected by global cross-region inference.
* This global routing is used to optimize resource availability and allow consistent performance for experimental model launches.
Data encryption
This topic provides information specific to Kiro about encryption in transit and encryption at rest.
Encryption in transit
All communication between customers and Kiro and between Kiro and its downstream dependencies is protected using TLS 1.2 or higher connections.
Encryption at rest
Kiro encrypts your data using AWS owned encryption keys from AWS Key Management Service (AWS KMS). You don't have to take any action to protect the AWS managed keys that encrypt your data. For more information, see AWS owned keys in the AWS Key Management Service Developer Guide .
When you subscribe with Kiro enterprise, administrators have the option to create customer managed keys to encrypt your data. Customer managed keys are KMS keys in your AWS account that you create, own, and manage to directly control access to your data by controlling access to the KMS key. Only symmetric keys are supported. For information on creating your own KMS key, see Creating keys in the AWS Key Management Service Developer Guide .
To set up a customer managed key to encrypt data as a Kiro enterprise administrator, you need permissions to use AWS KMS. The required KMS permissions are included in the example IAM policy . After creating a customer managed KMS key, you must provide the key in the Kiro console to use it to encrypt data.
Service improvement
To help Kiro provide the most relevant information, we may use certain content from Kiro, such as questions that you ask Kiro, other inputs you provide, and the responses and code that Kiro generates, for service improvement. This page explains what content we use and how to opt out.
Kiro content used for service improvement
We may use certain content from Kiro Free Tier and Kiro individual subscribers for service improvement. Users that have a paid Kiro subscription and access it through a social login provider (like GitHub or Google) or through AWS Builder ID are considered individual subscribers . Content that Kiro may use for service improvement includes, for example, your questions to Kiro, other inputs you provide, and the responses and code that Kiro generates. Kiro may use this content, for example, to provide better responses to common questions, fix Kiro operational issues, for de-bugging, or for model training.
We do not use content from Kiro enterprise users for service improvement.
Info
If you have an Amazon Q Developer Pro subscription and access Kiro through your AWS account with the Amazon Q Developer Pro subscription, then Kiro will not use your content for service improvement.
Opt out of data sharing
By default, Kiro collects usage data, errors, crash reports, and other metrics as well as content for service improvement from Kiro Free Tier users and Kiro individual subscribers. This section explains how to opt out of sharing your data in Kiro for Kiro Free Tier and Kiro individual subscribers. For information on how Kiro uses this data, see Kiro service improvement .
Kiro enterprise users are automatically opted out of telemetry and content collection by AWS. Telemetry collection settings for user activity reports are controlled by the administrator in the Kiro console and cannot be configured by Kiro enterprise users. For more information, see Kiro enterprise settings .
Info
If you are a Kiro Free Tier user, opting out of sharing your data for service improvement does not affect our ability to store your inputs for abuse detection purposes as described in more detail here .
Opting out of sharing data
IDE CLI Web
To opt out of sharing your client-side telemetry and content in the Kiro IDE:
* Open Settings in Kiro.
* Switch to the User sub-tab.
* Choose Application , and then choose Telemetry and Content .
* To opt out of telemetry collection, uncheck the box for Data Sharing and Prompt Logging: Usage Analytics And Performance Metrics . To opt out of content collection, uncheck the box for Data Sharing and Prompt Logging: Content Collection for Service Improvement .
Types of telemetry collected
* Usage data — Information such as the Kiro version, operating system (Windows, Linux, or macOS), and the anonymous machine ID.
* Performance metrics — The request count, errors, and latency for various features:
* Login
* Tab completion
* Code generation
* Steering
* Hooks
* Spec generation
* Tools
* MCP
Kiro Abuse Detection
In addition to the abuse detection mechanisms implemented through Amazon Bedrock that apply to all Kiro users across all models (see here for more details about abuse detection on Amazon Bedrock):
* Only with respect to Kiro Free Tier users, we may use additional abuse detection mechanisms designed to detect activity that violates our terms of service or use policies. Accordingly, for Free Tier users we may store your inputs for up to 60 days for the purposes of detecting activity that violates the Agreement and improving our ability to detect such activity. We will not use such inputs to improve Kiro's underlying generative AI models, but we may use your inputs to develop and improve classifier tools designed to detect abuse.
* For OpenAI GPT models, classifier-flagged traffic will be retained for up to 30 days for automated offline abuse detection. Retained traffic is stored in the region where your inference was processed.
Abuse, or failure to address abuse, of Kiro or models available via Kiro may result in suspension or termination of your access to Kiro. If you believe that your use has been inaccurately identified as in violation of our terms and policies, contact support for assistance.
Page updated: August 4, 2026
Privacy and Security
Code references
Links found on this page
- About Kiro [direct]
- IDE [direct]
- CLI [direct]
- Web [direct]
- Mobile [direct]
- Crew [direct]
- Pricing [direct]
- Downloads [direct]
- Enterprise [direct]
- Startups [direct]
- Students [direct]
- Overview [direct]
- Ambassadors [direct]
- Discord [direct]
- Events [direct]
- Powers [direct]
- Shop [direct]
- Showcase [direct]
- Docs [direct]
- Blog [direct]
- Changelog [direct]
- FAQs [direct]
- Report a bug [direct]
- Suggest an idea [direct]
- Billing support [direct]
- Site Terms [direct]
- License [direct]
- Responsible AI Policy [direct]
- Legal [direct]
- Privacy Policy [direct]
- Cookie Preferences [direct]
- Loading image... [direct]
- SIGN IN [direct]
- Installation [direct]
- Authentication [direct]
- Your first project [direct]
- Overview [direct]
- Available models [direct]
- Reasoning effort [direct]
- How Kiro works [direct]
- Specs [direct]
- Steering [direct]
- Hooks [direct]
- MCP [direct]
- Permissions [direct]
- Custom agents [direct]
- Agent Skills [direct]
- Powers [direct]
- Cloud sessions [direct]
- Compaction [direct]
- Kiroignore [direct]
- Checkpoints and rewind [direct]
- Built-in tools [direct]
- Configuration scopes [direct]
- What's new in 1.0 [direct]
- Setup & First Run [direct]
- Editor [direct]
- Chat [direct]
- Experimental [direct]
- Troubleshooting [direct]
- 0.x reference [direct]
- What's new in 3.0 [direct]
- Setup & First Run [direct]
- Terminal UI [direct]
- Chat [direct]
- Voice mode [direct]
- Headless mode [direct]
- ACP [direct]
- Auto complete [direct]
- Experimental [direct]
- 2.x reference [direct]
- Quick start [direct]
- Installation [direct]
- Running 24/7 [direct]
- Chat [direct]
- Agent Capabilities [direct]
- Features [direct]
- Interfaces [direct]
- Apps [direct]
- System & storage [direct]