FAQs | AWS CloudHSM | Amazon Web Services (AWS)

AWS has a limited credential to the HSM that permits us to monitor and maintain the health and availability of the HSM, take encrypted backups, and to extract and publish audit logs to your CloudWatch Logs AWS has no access to any keys or data inside your CloudHSM cluster and cannot perform any operations other than those allowed for an HSM …

https://aws.amazon.com/cloudhsm/faqs/