← Trust Directory

Amazon Web Services

aws.amazon.com · 3 assessments

Amazon Web Services - organisation
Approve
No blocking issues found in the public evidence
Assessed Aug 28, 2026 · public evidence coverage 53% · evidence confidence medium high · methodology 0.6.1

Products assessed

A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.

Amazon Bedrock
Approve with conditions
1 item to confirm in writing
Assessed Aug 28, 2026 · public evidence coverage 50% · evidence confidence medium high · methodology 0.6.0
Amazon Q
Approve with conditions
3 items to confirm in writing
Assessed Aug 31, 2026 · public evidence coverage 45% · evidence confidence medium · methodology 0.6.1

Certifications

What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.

ISO/IEC 27001
Claimed & corroborated

ISO/IEC 27001:2022, Ernst & Young CertifyPoint B.V., RvA-accredited (Dutch Accreditation Council), certificate 2013-009, Active, record last updated 16 Jan 2026. SCOPE LIMITATION OF THE RECORD: the registry entry lists only the certified entity and its Seattle main site, with no scope-of-registration statement and no technical sectors - it does not state which AWS services the ISMS covers. Ask AWS for the certificate with its scope statement to establish service coverage.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · IAF CertSearch · checked Aug 24, 2026

ISO/IEC 27017
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · ISO/IEC 27017:2015 certificate 2015-015 (AWS Artifact download supplied by Robbo 2026-08-28) · checked Aug 28, 2026

Valid until Nov 30, 2028

ISO/IEC 27018
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · ISO/IEC 27018:2019 certificate held in the TrustyCyber vault (AWS Artifact) · checked Aug 28, 2026

Valid until Nov 30, 2028

SOC 2 Type 2
Claimed & corroborated

Published report; access via AWS Artifact.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact) · checked Aug 28, 2026

CSA STAR Level 2
Claimed & corroborated

Stated on the Bedrock FAQ.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · CSA STAR Registry · checked Aug 28, 2026

FedRAMP
Claimed & corroborated

Named in the 143-programme list; per-service scope on the services-in-scope page.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · AWS FedRAMP Customer Package held in the TrustyCyber vault (AWS Artifact) · checked Aug 28, 2026

PCI DSS
Claimed & corroborated

Named in the 143-programme list.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · Visa Global Registry of Service Providers · checked Aug 24, 2026

Valid until Dec 31, 2026

ISO/IEC 42001
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (AWS Artifact) · checked Aug 24, 2026

Valid until Nov 14, 2027

ISO/IEC 27701
Claimed & corroborated

ISO/IEC 27701:2019 (privacy information management system), Ernst & Young CertifyPoint B.V., RvA-accredited, certificate 2021-035, Active, record last updated 16 Jan 2026. SCOPE LIMITATION OF THE RECORD: entity and Seattle main site only, no scope-of-registration statement and no technical sectors - the record does not state which AWS services the PIMS covers, nor whether AWS is certified as PII controller or processor.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · IAF CertSearch · checked Aug 24, 2026

SOC 2
Claimed & corroborated

SOC 2 Type 2 by EY (Ernst & Young), period 1 Apr 2025 - 31 Mar 2026 (current), trust services criteria security, availability, confidentiality and privacy. Type 2: controls both suitably designed AND operating effectively across the period. The report defines a specific in-scope AWS service list and does not blanket every AWS service - check that list before relying on it for a particular service. Vault: Gated/AWS/2026-03_aws-soc2-type2-ey.pdf.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact) · checked Aug 24, 2026

CSA STAR
Claimed & corroborated

CSA STAR Registry: AWS holds both STAR Level 1 (CAIQ self-assessment v4.0.2) and STAR Level 2 (STAR Certification v4.0, a third-party certification combining ISO/IEC 27001 with the CSA Cloud Controls Matrix). Level 2 created or renewed 20 April 2026; listed since 11 June 2020.

  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · CSA STAR Registry · checked Aug 24, 2026

EU-U.S. Data Privacy Framework
Claimed & corroborated
  • Vendor claimed
  • Evidence cited
  • Registry corroborated
  • Scope verified
  • Current

Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Aug 28, 2026

Valid until Jan 2, 2027

Supply chain

Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.

AI providers: AI21 Labs, Anthropic, Cohere, DeepSeek, Luma AI, Meta, Mistral AI, OpenAI, Stability AI, TwelveLabs, Writer
Models: Amazon (Amazon FMs)

How to read this

This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. This record reflects the evidence available on Aug 28, 2026.