Kinesis Data Stream is not encrypted

A monitor to identify unencrypted Kinesis Data Streams.

Dashbird continuously monitors and analyses your serverless applications to ensure reliability, cost and performance optimisation and alignment with the Well Architected Framework.

Product Features Start Free Trial
Interval: 1 day
Severity: INFO

Why do I see this?

You didn’t enable server-side encryption (SSE) for one of your streams.

What does this mean?

Kinesis Data Stream can use SSE to encrypt all data at rest before its stored in Kinesis streams’ storage layer. Leaving it unencrypted is a security risk and should be avoided.

Kinesis Data Stream is not encrypted. How do I fix this?

You can enable SSE for a steam in the AWS Console.


This rule resolution is part of the Dashbird Serverless Well Architected Reports tool for AWS. Dashbird features a collection of rules and checks continuously applied to your infrastructure, surfacing ways to improve it.

Monitor and analyze AWS Kinesis streams and learn the best practice rules for AWS Kinesis.

Industry leader in serverless monitoring

Dashbird is a monitoring, debugging and intelligence platform designed to help serverless developers build, operate, improve, and scale their modern cloud applications on AWS environment securely and with ease.