Products assessed
A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.
Certifications
What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.
ISO/IEC 27001:2022, Ernst & Young CertifyPoint B.V., RvA-accredited (Dutch Accreditation Council), certificate 2013-009, Active, record last updated 16 Jan 2026. SCOPE LIMITATION OF THE RECORD: the registry entry lists only the certified entity and its Seattle main site, with no scope-of-registration statement and no technical sectors - it does not state which AWS services the ISMS covers. Ask AWS for the certificate with its scope statement to establish service coverage.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · IAF CertSearch · checked Aug 24, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- ✓ Current
Verified on the registry · ISO/IEC 27017:2015 certificate 2015-015 (AWS Artifact download supplied by Robbo 2026-08-28) · checked Aug 28, 2026
Valid until Nov 30, 2028
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- ✓ Current
Verified on the registry · ISO/IEC 27018:2019 certificate held in the TrustyCyber vault (AWS Artifact) · checked Aug 28, 2026
Valid until Nov 30, 2028
Published report; access via AWS Artifact.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- — Current
Verified on the registry · SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact) · checked Aug 28, 2026
Stated on the Bedrock FAQ.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · CSA STAR Registry · checked Aug 28, 2026
Named in the 143-programme list; per-service scope on the services-in-scope page.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- — Current
Verified on the registry · AWS FedRAMP Customer Package held in the TrustyCyber vault (AWS Artifact) · checked Aug 28, 2026
Named in the 143-programme list.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- ✓ Current
Verified on the registry · Visa Global Registry of Service Providers · checked Aug 24, 2026
Valid until Dec 31, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- ✓ Current
Verified on the registry · ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (AWS Artifact) · checked Aug 24, 2026
Valid until Nov 14, 2027
ISO/IEC 27701:2019 (privacy information management system), Ernst & Young CertifyPoint B.V., RvA-accredited, certificate 2021-035, Active, record last updated 16 Jan 2026. SCOPE LIMITATION OF THE RECORD: entity and Seattle main site only, no scope-of-registration statement and no technical sectors - the record does not state which AWS services the PIMS covers, nor whether AWS is certified as PII controller or processor.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · IAF CertSearch · checked Aug 24, 2026
SOC 2 Type 2 by EY (Ernst & Young), period 1 Apr 2025 - 31 Mar 2026 (current), trust services criteria security, availability, confidentiality and privacy. Type 2: controls both suitably designed AND operating effectively across the period. The report defines a specific in-scope AWS service list and does not blanket every AWS service - check that list before relying on it for a particular service. Vault: Gated/AWS/2026-03_aws-soc2-type2-ey.pdf.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- — Current
Verified on the registry · SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact) · checked Aug 24, 2026
CSA STAR Registry: AWS holds both STAR Level 1 (CAIQ self-assessment v4.0.2) and STAR Level 2 (STAR Certification v4.0, a third-party certification combining ISO/IEC 27001 with the CSA Cloud Controls Matrix). Level 2 created or renewed 20 April 2026; listed since 11 June 2020.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · CSA STAR Registry · checked Aug 24, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- ✓ Scope verified
- ✓ Current
Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Aug 28, 2026
Valid until Jan 2, 2027
Supply chain
Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.
How to read this
This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. This record reflects the evidence available on Aug 28, 2026.
