But how do you guarantee encryption at all stages such that Amazon cannot snoop it when you have to do final mile encryption on hardware controlled by Amazon?
I mean encryption for messenger services where each end is not controlled by a third-party is one thing...but how do you guarantee the third-party in control of the hardware responsible for performing the encryption isn't snooping?
The only thing I can think of (and again this isn't my strongest area) is to not handle any data on an Amazon server that isn't already encrypted...but how does that work if you are using a service like RDS or Redshift?
And even if you could work out a super complicated security-conscious solution...is it unreasonable for Walmart to not trust all it's vendors to take such extreme measures and therefore just create a general policy against the use of AWS?