AWS – Introducing support for AWS KMS customer managed keys for encrypting artifacts by Amazon CloudWatch Synthetics
CloudWatch Synthetics now supports using an AWS Key Management Service (AWS KMS) key that you provide to encrypt the canary run data that CloudWatch Synthetics stores in your Amazon Simple Storage Service (Amazon S3) bucket. By default, these artifacts are encrypted at rest using an AWS managed key.
Read More for the details.