The quarantine policy protects AWS’s invoice, not your data.
When AWS finds your key in public it attaches AWSCompromisedKeyQuarantineV3. Diffing the three versions since 2020 shows the deny list growing from 28 to 99 actions, no action ever removed, and beyond S3 reads, not one of the twenty-one data-access actions we checked has ever been denied. sts:AssumeRole and secretsmanager:GetSecretValue still work.
