Ring’s new default encryption approach is designed to retain cloud-based video features and shared-user workflows while limiting how long Ring’s cloud retains the keys needed to process footage.

Key takeaways

  • Ring announced TAKE, or Throw Away the Key Encryption, on August 26, 2026, with phased customer rollout beginning in September.
  • Under TAKE, Ring says cloud-held content encryption keys rotate frequently and are deleted on a rolling 24-hour basis.
  • For processing older video after that window, Ring says its app supplies the needed keys only after a customer-initiated action; those session keys are discarded after processing.
  • TAKE is not end-to-end encryption: Ring’s cloud remains a controlled member of each camera’s encryption group while TAKE is enabled so cloud features can operate.
  • End-to-end encryption remains an optional per-camera mode, but it excludes Shared Users and cloud-dependent functions such as Video Search and Smart Video Descriptions.

A new default for Ring cloud video

Ring announced TAKE, short for Throw Away the Key Encryption, on August 26, 2026. The Amazon-owned camera maker describes the system as its new default encryption architecture for cloud-stored video, with phased rollout to customers beginning in September. Ring says TAKE will become the worldwide default once the rollout is complete, while its existing end-to-end encryption (E2EE) mode will remain optional. ([aboutamazon.com](https://www.aboutamazon.com/news/devices/ring-take-encryption))

The change is significant because it targets a familiar cloud-video trade-off. Strict E2EE keeps decryption keys away from the service provider, but it can also prevent server-side functions and complicate multi-user access. Ring’s stated goal is to reduce the duration and scope of its cloud access to video keys without withdrawing features that depend on cloud processing. ([aboutamazon.com](https://www.aboutamazon.com/news/devices/ring-take-encryption))

How TAKE handles keys

According to Ring’s August 26 technical white paper, each camera’s video is protected with frequently changing keys, including content encryption keys derived for five-minute intervals. Under TAKE, a Ring cloud member is present in the camera’s encryption group and can derive keys needed for enabled cloud features, such as Smart Alerts, Video Search and Smart Video Descriptions. ([assets.aboutamazon.com](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf))

Ring says the cloud-held key material is managed in AWS Nitro Enclaves and that access is restricted to approved feature processing. Its design calls for a rolling 24-hour retention window: as keys age out, the company says its key-management service ratchets forward secrets and permanently discards the prior material. Ring states that after expiration, its cloud cannot independently access content encrypted under those keys. ([assets.aboutamazon.com](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf))

Customer action matters after the 24-hour window

TAKE does not mean cloud features are permanently unable to work on older clips. Ring’s documentation says that if a customer initiates an action requiring cloud processing—such as playback, sharing a recording or authorizing analysis of historical footage—the Ring app identifies and supplies the necessary keys to the relevant cloud service. Ring says this delivery is push-only: its cloud cannot request a device to release a key on its own. The supplied key is not retained after the processing session ends. ([assets.aboutamazon.com](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf))

That distinction is important for buyers evaluating privacy claims. TAKE is a key-lifecycle and access-control architecture, not a claim that Ring’s cloud can never decrypt video. During the defined 24-hour period, and later when a customer-triggered activity supplies a key, cloud services can process footage for functions the customer has enabled. Ring positions E2EE, rather than TAKE, as the mode in which its cloud never receives decryption keys. ([assets.aboutamazon.com](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf))

Shared users, older cameras and deployment planning

For households or small sites that need delegated access, TAKE is meant to retain Shared Users. Ring says a newly added Shared User can decrypt video recorded after being granted access, and removal takes that user out of the relevant camera encryption group so future content is protected with new group keys. The company’s architecture uses Messaging Layer Security (MLS), an IETF standards-track group key-establishment protocol built for changing membership and asynchronous participants. ([assets.aboutamazon.com](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf))

Installers and buyers should also note the hardware distinction in Ring’s paper. Newer cameras with encryption-capable firmware encrypt footage on the device before transmission and can support TAKE or E2EE. Older cameras instead encrypt at cloud ingress under the TAKE design; Ring says those units support TAKE but not E2EE. A mixed installed base may therefore have different encryption-mode choices even after TAKE becomes broadly available. ([assets.aboutamazon.com](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf))

What procurement teams should verify

Organizations using Ring equipment should treat the rollout as a configuration and governance review rather than as a simple firmware update. Confirm which cameras are eligible when an account receives its invitation, determine whether shared-user access and cloud analytics are operational requirements, and document the recovery method for account-held encryption keys. Ring says supported customers can manage encryption settings per camera, and that recovery options will become fully available over the rollout period. ([aboutamazon.com](https://www.aboutamazon.com/news/devices/ring-take-encryption))

For privacy-sensitive deployments, decision-makers should assess the practical difference between the two modes. TAKE preserves Ring’s cloud features through bounded and customer-authorized key access; E2EE removes Ring’s cloud member but also removes Shared Users and cloud video-analysis functions. Teams should align the selected mode with their video-retention policy, access-control model, incident-response procedures and any contractual or regulatory obligations governing recorded video. ([assets.aboutamazon.com](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf))