Their primary feature is tamper-resistant key management. It means you can store your keys in a data centre - where people you don't fully trust may have physical hardware access - yet still have an expectation of security. Something like this is useful whether you use Amazon or a traditional data center.