We manage keys, but we don't store data.
All crypto operations and encrypted data processing happens inside TEEs (AWS Nitro Enclaves, specifically [0]). Using Relay, you can pass data on to trusted third parties over TLS. With Cages, you can deploy custom code inside a TEE which can process data in whichever way you need.
For developers who don't want plaintext data on our infrastructure, we also provide SDKs which let them encrypt data using our PKI scheme — on their own infrastructure.
[0]: https://press.aboutamazon.com/news-releases/news-release-det...