But how do you guarantee encryption at all stages such that Amazon cannot snoop it when you have to do final mile encryption on hardware controlled by Amazon?
I mean encryption for messenger services where each end is not controlled by a third-party is one thing...but how do you guarantee the third-party in control of the hardware responsible for performing the encryption isn't snooping?
The only thing I can think of (and again this isn't my strongest area) is to not handle any data on an Amazon server that isn't already encrypted...but how does that work if you are using a service like RDS or Redshift?
And even if you could work out a super complicated security-conscious solution...is it unreasonable for Walmart to not trust all it's vendors to take such extreme measures and therefore just create a general policy against the use of AWS?
That said, it's not illegal for them to see that xxx vendor increased their storage costs/bandwidth costs by $yyy every month, and that you could look into it - without using one piece of encrypted data.
Disclosure: Former AWS
It's true of anyone selling bare metal servers too, it is just harder to snoop but the technology exists to do so.