@neil @jmtd @pwaring @beasts yup - KMS is the AWS service that provides the encryption keys:
https://docs.aws.amazon.com/kms/latest/developerguide/data-protection.html
"There is no mechanism for anyone, including AWS service operators, to view, access, or export plaintext key material. This principle applies even during catastrophic failures and disaster recovery events. Plaintext customer key material in AWS KMS is used for cryptographic operations within AWS KMS FIPS validated HSMs only in response to authorized requests made to the service by the customer or their delegate"