AWS

aws.amazon.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
65 / 100C
Procurement decision
Approve
Evidence Medium HighFreshness CurrentVerification Partial

Scanned Aug 28, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

Will they train on your data?Clear

Tuning uses a private model copy; customer data is not shared with model providers and is not used to improve the base models.

Evidence
When you tune a foundation model, we base it on a private copy of that model. This means your data is not shared with model providers, and is not used to improve the base models.
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
We do not access or use your content for any purpose without your agreement. We do not use your content or derive information from it for marketing or advertising purposes.
With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.
How long do they keep your data?Clear

The service terms commit to deleting customer content following account closure, per service documentation.

Evidence
Vendor publishedAWS Service Termsretrieved Aug 28, 2026
Following closure of your AWS account, we will delete Your Content in accordance with the technical documentation applicable to the Services.
Who else can access your data?Clear

AWS commits to not disclosing customer content unless legally compelled, redirecting government demands to the customer where possible.

Evidence
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
We will not disclose customer content (see How does AWS classify customer information? below) unless we're required to do so to comply with the law or a valid and binding order of a government body. If a governmental body sends AWS a demand for your customer content, we will attempt to redirect the governmental body to request that data directly
Vendor publishedAmazon Web Services (AWS) Sub-processorsretrieved Aug 28, 2026
AWS will update this page at least 30 days before engaging a new sub-processor, and if you subscribe for updates , AWS will notify you by email of changes to this page.
Which FMs are available in Amazon Bedrock? Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today. This includes models from: AI21 Labs Amazon Anthropic Cohere DeepSeek Luma AI Meta Mistral AI OpenAI poolsid e (coming soon) Stability AI TwelveLabs Writer
!Where is your data processed?Ask the vendor

The customer chooses storage Region(s); AWS will not move or replicate content outside them without agreement.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.
Vendor publishedAWS Service Termsretrieved Aug 28, 2026
To improve performance, such services may use cross-region inference, using the optimal AWS Region to process your Content when running model inference.
Customized FMs remain in the Region where the API call is processed.
What happens in a security incident?Clear

AWS documents a security incident monitoring and data breach notification process, committing to notify customers of breaches of AWS security without undue delay per the DPA.

Evidence
Vendor publishedGDPR - Amazon Web Services (AWS)retrieved Aug 28, 2026
AWS has a security incident monitoring and data breach notification process in place and will notify customers of breaches of AWS’s security without undue delay and in accordance with the AWS DPA.

Key findingsclick a row for the evidence

Customer-content commitments are unusually concreteStrong

AWS commits in plain terms to Region choice with no movement without agreement, no access or use of content without agreement, deletion on account closure, and legal-demand redirection with notice.

These are contractual-grade answers to the questions buyers usually have to negotiate for.

Evidence
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
We do not access or use your content for any purpose without your agreement. We do not use your content or derive information from it for marketing or advertising purposes.
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
We will not disclose customer content (see How does AWS classify customer information? below) unless we're required to do so to comply with the law or a valid and binding order of a government body. If a governmental body sends AWS a demand for your customer content, we will attempt to redirect the governmental body to request that data directly
Vendor publishedAWS Service Termsretrieved Aug 28, 2026
Following closure of your AWS account, we will delete Your Content in accordance with the technical documentation applicable to the Services.
Breach notification is committed, not aspirationalStrong

The GDPR centre documents a monitoring and breach-notification process with a without-undue-delay commitment anchored to the DPA.

Incident-response commitments anchored in the DPA are enforceable, unlike page prose.

Evidence
Vendor publishedGDPR - Amazon Web Services (AWS)retrieved Aug 28, 2026
AWS has a security incident monitoring and data breach notification process in place and will notify customers of breaches of AWS’s security without undue delay and in accordance with the AWS DPA.
!Organisation-level AI change management is not evidencedGap

Model lifecycle commitments exist at the Bedrock product level, but no organisation-wide AI change or deprecation policy was found in the collected sources.

AWS ships AI features across dozens of services under the service terms; buyers of non-Bedrock AI features have no equivalent lifecycle commitment.

Question for vendor: Do the Bedrock model-lifecycle commitments (12-month availability, 6-month legacy notice) extend to AI features embedded in other AWS services?

Evidence
Vendor publishedAWS Service Termsretrieved Aug 28, 2026
Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex,
!Cross-region inference qualifies the residency storyGap

Region-of-use storage commitments coexist with service terms allowing cross-region inference for Bedrock-powered features.

A buyer relying on strict residency needs to confirm cross-region inference is disabled or acceptable for their deployment.

Question for vendor: Which generative AI features use cross-region inference by default, and how is it disabled?

Evidence
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.
Vendor publishedAWS Service Termsretrieved Aug 28, 2026
To improve performance, such services may use cross-region inference, using the optimal AWS Region to process your Content when running model inference.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the score80
Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
Vendor publishedResponsible AI – Building AI Responsibly – AWSretrieved Aug 28, 2026
AWS defines responsible AI using a core set of dimensions that we assess and update over time as AI technology evolves.
Vendor publishedResponsible AI – Building AI Responsibly – AWSretrieved Aug 28, 2026
G7 AI Hiroshima Process Code of Conduct , AI Safety Summit in the UK , and support for ISO 42001 , a new foundational standard to advance responsible AI.
Vendor publishedGDPR - Amazon Web Services (AWS)retrieved Aug 28, 2026
Cloud Infrastructure Services Providers in Europe (CISPE) Data Protection Code of Conduct Public Register includes a list of adherent AWS services.

Governance & accountability: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI system15% of the score27
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
With Amazon Bedrock, you have full control over the data you use to customize the foundation models for your generative AI applications.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
Vendor publishedResponsible AI – Building AI Responsibly – AWSretrieved Aug 28, 2026
Amazon SageMaker Clarify helps you mitigate bias by detecting potential bias during data preparation, after model training, and in your deployed model by examining specific attributes.
Vendor publishedResponsible AI – Building AI Responsibly – AWSretrieved Aug 28, 2026
Amazon Bedrock Guardrails helps you implement safeguards customized to your application requirements and responsible AI policies. With industry-leading safety protections that block up to 88% of harmful content and deliver auditable, mathematically verifiable explanations for validation decisions with 99% accuracy,
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Not Evidenced

Change management: not publicly evidenced.

Model10% of the score40
Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
Which FMs are available in Amazon Bedrock? Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today. This includes models from: AI21 Labs Amazon Anthropic Cohere DeepSeek Luma AI Meta Mistral AI OpenAI poolsid e (coming soon) Stability AI TwelveLabs Writer
Customer data15% of the score85
Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
When you tune a foundation model, we base it on a private copy of that model. This means your data is not shared with model providers, and is not used to improve the base models.
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
We do not access or use your content for any purpose without your agreement. We do not use your content or derive information from it for marketing or advertising purposes.
Vendor publishedGDPR - Amazon Web Services (AWS)retrieved Aug 28, 2026
We offer customers strong encryption for customer data in transit or at rest, and we provide customers with the option to manage their own encryption keys.
Vendor publishedAWS Service Termsretrieved Aug 28, 2026
To improve performance, such services may use cross-region inference, using the optimal AWS Region to process your Content when running model inference.
Vendor publishedAWS Service Termsretrieved Aug 28, 2026
Following closure of your AWS account, we will delete Your Content in accordance with the technical documentation applicable to the Services.
With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.
Customized FMs remain in the Region where the API call is processed.

Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

AI supply chain10% of the score60
Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedGDPR - Amazon Web Services (AWS)retrieved Aug 28, 2026
Yes, AWS may use three types of sub-processors: (1) AWS entities that provide the infrastructure on which the AWS services run; (2) AWS entities that support specific AWS services which may require these entities to process customer data;
Vendor publishedAmazon Web Services (AWS) Sub-processorsretrieved Aug 28, 2026
AWS will update this page at least 30 days before engaging a new sub-processor, and if you subscribe for updates , AWS will notify you by email of changes to this page.

Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.

Security foundation15% of the score65
Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedGDPR - Amazon Web Services (AWS)retrieved Aug 28, 2026
AWS has a security incident monitoring and data breach notification process in place and will notify customers of breaches of AWS’s security without undue delay and in accordance with the AWS DPA.
Independent assurance evidence10% of the score100
Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedCloud Compliance - Amazon Web Services (AWS)retrieved Aug 28, 2026
AWS supports 143 security standards and compliance certifications, including PCI-DSS, HIPAA/HITECH, FedRAMP, GDPR, FIPS 140-3, and NIST 800-171, helping customers satisfy compliance requirements around the globe.
Vendor publishedCloud Compliance - Amazon Web Services (AWS)retrieved Aug 28, 2026
Get on-demand access to AWS and ISV security and compliance reports by using AWS Artifact. Find auditor-issued reports, certifications, accreditations, and other third-party attestations of AWS in a comprehensive resource.
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
AWS complies with ISO 27018, a code of practice that focuses on protection of personal data in the cloud. It extends ISO information security standard 27001 to cover the regulatory requirements for the protection of personally identifiable information (PII) or personal data for the public cloud computing environment
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
AWS publishes a SOC 2 Type II report, developed by the American Institute of CPAs (AICPA), which establishes criteria for evaluating controls related to how personal data is collected, used, retained, disclosed, and disposed to meet the entity’s objectives. The AWS SOC 2 Type II report provides third-party attestation of our systems and the suitability of the design of our controls.
Amazon Bedrock is included in the scope of the SOC 1, 2, 3 reports,
Vendor publishedGDPR - Amazon Web Services (AWS)retrieved Aug 28, 2026
Examples of this include AWS' ISO 27001 , 27017, and 27018 compliance.
Amazon Bedrock is CSA Security Trust Assurance and Risk (STAR) Level 2 certified, which validates the use of best practices and the security posture of AWS cloud offerings.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Aug 28, 2026

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 27001retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedIAF CertSearch record — ISO/IEC 27701retrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STARretrieved Aug 24, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Document held and reviewed by TrustyCyber — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Legal & contractual10% of the score60
Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedData Privacy - Amazon Web Services (AWS)retrieved Aug 28, 2026
We will not disclose customer content (see How does AWS classify customer information? below) unless we're required to do so to comply with the law or a valid and binding order of a government body. If a governmental body sends AWS a demand for your customer content, we will attempt to redirect the governmental body to request that data directly
Vendor publishedGDPR - Amazon Web Services (AWS)retrieved Aug 28, 2026
continue to rely on the SCCs for any transfer of customer data outside the EEA in compliance with GDPR.
Vendor publishedAWS Service Termsretrieved Aug 28, 2026
Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex,

Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Publish Change management evidenceAI System 2747
+3Complete the Vulnerability & incident handling disclosureSecurity Foundation 6585
+2Have Customer data treatment disclosures independently corroboratedData 85100
+2Have Governance & accountability disclosures independently corroboratedOrganisation 8095
+2Complete the Model provider transparency disclosureModel 4060

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 65 → up to 82 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSAmazon Web ServicesAmazon Web ServicesAmazon BedrockAmazon BedrockAI21 LabsAI21 LabsAmazon (Amazon FMs)Amazon (Amazon FMs)AnthropicAnthropicCohereCohereDeepSeekDeepSeekLuma AILuma AIMetaMetaMistral AIMistral AIOpenAIOpenAIStability AIStability AITwelveLabsTwelveLabsWriterWriter
View as list
Amazon Bedrock Uses AI Service AI21 Labs
Amazon Bedrock Uses AI Service Amazon (Amazon FMs)
Amazon Bedrock Uses AI Service Anthropic
Amazon Bedrock Uses AI Service Cohere
Amazon Bedrock Uses AI Service DeepSeek
Amazon Bedrock Uses AI Service Luma AI
Amazon Bedrock Uses AI Service Meta
Amazon Bedrock Uses AI Service Mistral AI
Amazon Bedrock Uses AI Service OpenAI
Amazon Bedrock Uses AI Service Stability AI
Amazon Bedrock Uses AI Service TwelveLabs
Amazon Bedrock Uses AI Service Writer

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 12 — registry checks and verification ladders, click to view
ISO/IEC 27001Claimed & corroborated

ISO/IEC 27001:2022, Ernst & Young CertifyPoint B.V., RvA-accredited (Dutch Accreditation Council), certificate 2013-009, Active, record last updated 16 Jan 2026. SCOPE LIMITATION OF THE RECORD: the registry entry lists only the certified entity and its Seattle main site, with no scope-of-registration statement and no technical sectors - it does not state which AWS services the ISMS covers. Ask AWS for the certificate with its scope statement to establish service coverage.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against IAF CertSearch, Aug 24, 2026: Verified on the registry

ISO/IEC 27017Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Nov 30, 2028

Checked against ISO/IEC 27017:2015 certificate 2015-015 (AWS Artifact download supplied by Robbo 2026-08-28), Aug 28, 2026: Verified on the registry

ISO/IEC 27018Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Nov 30, 2028

Checked against ISO/IEC 27018:2019 certificate held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry

SOC 2 Type 2Claimed & corroborated

Published report; access via AWS Artifact.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated

Stated on the Bedrock FAQ.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry

FedRAMPClaimed & corroborated

Named in the 143-programme list; per-service scope on the services-in-scope page.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against AWS FedRAMP Customer Package held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry

PCI DSSClaimed & corroborated

Named in the 143-programme list.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Dec 31, 2026

Checked against Visa Global Registry of Service Providers, Aug 24, 2026: Verified on the registry

ISO/IEC 42001Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Nov 14, 2027

Checked against ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (AWS Artifact), Aug 24, 2026: Verified on the registry

ISO/IEC 27701Claimed & corroborated

ISO/IEC 27701:2019 (privacy information management system), Ernst & Young CertifyPoint B.V., RvA-accredited, certificate 2021-035, Active, record last updated 16 Jan 2026. SCOPE LIMITATION OF THE RECORD: entity and Seattle main site only, no scope-of-registration statement and no technical sectors - the record does not state which AWS services the PIMS covers, nor whether AWS is certified as PII controller or processor.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against IAF CertSearch, Aug 24, 2026: Verified on the registry

SOC 2Claimed & corroborated

SOC 2 Type 2 by EY (Ernst & Young), period 1 Apr 2025 - 31 Mar 2026 (current), trust services criteria security, availability, confidentiality and privacy. Type 2: controls both suitably designed AND operating effectively across the period. The report defines a specific in-scope AWS service list and does not blanket every AWS service - check that list before relying on it for a particular service. Vault: Gated/AWS/2026-03_aws-soc2-type2-ey.pdf.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact), Aug 24, 2026: Verified on the registry

CSA STARClaimed & corroborated

CSA STAR Registry: AWS holds both STAR Level 1 (CAIQ self-assessment v4.0.2) and STAR Level 2 (STAR Certification v4.0, a third-party certification combining ISO/IEC 27001 with the CSA Cloud Controls Matrix). Level 2 created or renewed 20 April 2026; listed since 11 June 2020.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Aug 24, 2026: Verified on the registry

EU-U.S. Data Privacy FrameworkClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Jan 2, 2027

Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry

Sources 24 — click to view
Responsible AI – Building AI Responsibly – AWS
AI Documentation · Vendor · retrieved Aug 28, 2026
Secure Gen AI Apps - Amazon Bedrock Security and Privacy - AWS
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
GDPR - Amazon Web Services (AWS)
DPA · Vendor · retrieved Aug 28, 2026
Amazon Web Services (AWS) Sub-processors
Subprocessor List · Vendor · retrieved Aug 28, 2026
AWS Privacy Notice
Privacy Notice · Vendor · retrieved Aug 28, 2026
Cloud Compliance - Amazon Web Services (AWS)
Certification Or Compliance Page · Vendor · retrieved Aug 28, 2026
Reference Architecture Examples and Best Practices
Technical Architecture Documentation · Vendor · retrieved Aug 28, 2026
AWS Service Terms
Terms · Vendor · retrieved Aug 28, 2026
AWS Blogs - Cloud news & innovation | Amazon Web Services (AWS)
Technical Article · Vendor · retrieved Aug 28, 2026
Cloud Security – Amazon Web Services (AWS)
Trust Or Security Page · Vendor · retrieved Aug 28, 2026
Data Privacy - Amazon Web Services (AWS)
Privacy Notice · Vendor · retrieved Aug 28, 2026
IAF CertSearch record — ISO/IEC 27001
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
IAF CertSearch record — ISO/IEC 27701
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
CSA STAR Registry record — CSA STAR
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
Visa Global Registry of Service Providers record — PCI DSS
External Registry Or Certification Evidence · Registry · retrieved Aug 24, 2026
ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (AWS Artifact) record — ISO/IEC 42001
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact) record — SOC 2
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 24, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact) record — SOC 2 Type 2
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 28, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Aug 28, 2026
ISO/IEC 27018:2019 certificate held in the TrustyCyber vault (AWS Artifact) record — ISO/IEC 27018
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 28, 2026
AWS FedRAMP Customer Package held in the TrustyCyber vault (AWS Artifact) record — FedRAMP
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 28, 2026
ISO/IEC 27017:2015 certificate 2015-015 (AWS Artifact download supplied by Robbo 2026-08-28) record — ISO/IEC 27017
External Registry Or Certification Evidence · External Corroborating · retrieved Aug 28, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

Want to go further?

This scan assesses AWS at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.

Scan a specific product →

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.