Skip to content
Rush Commerce
Commerce & Retail Tech3 min read

Ring's TAKE encryption: who holds the keys to your footage

Ring made TAKE encryption the default for cloud video features, deleting keys within 24 hours. What key custody means for any vendor processing your business data.

If you have cameras on a storefront, a warehouse door, or a loading dock, a vendor is holding the decryption keys to that footage right now. Amazon's Ring just changed how long it holds them. Ring's TAKE encryption is worth reading not because you care about doorbells, but because key custody is the question you should be asking every vendor that processes your data.

What actually happened

Ring announced TAKE on August 26 — "Throw Away the Key Encryption" — and is making it the default for cloud video features. Rollout starts in September and becomes the worldwide default in phases.

The mechanism: cameras generate unique, rotating encryption keys. A copy goes into a secure cloud enclave so Ring can decrypt video long enough to run a requested feature, then the keys are deleted within 24 hours of the request completing. TechCrunch reports the scheme is built on Messaging Layer Security, an IETF standard. Ring's own framing is that it holds no permanent copy: you keep the keys, along with any shared users you enable.

The trade is that cloud features keep working. Smart Alerts, video search, video descriptions, live view, playback, and sharing all survive — which they do not under Ring's full end-to-end encryption, still available as an opt-in alternative. Account recovery runs through passphrases, passkeys, another approved device, or a cloud backup.

Why key custody matters for your business

Strip the branding and TAKE is a design pattern: hold the key only for the duration of the work, then throw it away. That is a middle position between "the vendor keeps a permanent copy so the AI features work" and "nobody but you can read anything, and the AI features do not exist."

Almost every AI vendor you use sits somewhere on that spectrum, and almost none of them tell you where without being asked. Your transcription vendor, your document processor, your support-ticket summarizer — each one decrypts something to do its job. The questions are the same every time: how long is the key held, where, who can reach the enclave, and what is deleted when the job finishes.

Ask them in writing. A vendor that has thought about it will answer in a paragraph. A vendor that has not will send you a marketing page about how seriously they take security. That difference is the whole signal.

Key takeaways

  • Ring's TAKE holds rotating keys in a cloud enclave and deletes them within 24 hours of a request
  • It preserves cloud AI features that full end-to-end encryption breaks; E2EE stays opt-in
  • Rollout begins September 2026 and becomes the global default in phases
  • The pattern generalizes: ephemeral key custody is a real middle ground worth demanding
  • Ask every AI vendor how long they hold your decryption keys — get the answer in writing

We read the data terms before we wire anything up. When we integrate a vendor into your stack, key handling and retention are part of the build spec, not an afterthought. Send us your vendor list and we'll tell you who's holding what or see how we scope integrations.

Sources: TechCrunch, About Amazon.

  • #security
  • #encryption
  • #retail-tech
  • #vendor-risk
  • #privacy
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.