This simulation demonstrates the principles of cloud security within a cloud computing environment through a concrete, well-defined mechanic: envelope encryption combined with IAM-gated key access. Every object in the storage bucket is protected by its own Data Encryption Key, which is itself wrapped by a master Key Encryption Key inside a KMS vault. Requests from Admin, Analyst and Attacker identities travel to the vault to ask it to unwrap a DEK; the KMS grants or denies each request against a simple IAM policy before any decryption happens. A direct-breach button lets you bypass the KMS entirely and read the storage bucket off disk, showing exactly why encryption-at-rest and access control are complementary, not interchangeable, defenses — and a live anomaly score tracks denied and breach events the way a real cloud threat-detection service would.