What are the possibilities to encrypt data at rest in AWS with the SaaS service?
Can an AWS KMS cross-account (customer-managed/AWS-managed/AWS-owned) CMKs be used that is provided by the customer? Other possibilities?

We do encryption at rest on the Elasticsearch Service, you can read more here -

As far as I know there's not currently a way to use your own keys for this. But I'll highlight your topic to the Product team as a request :slight_smile:

