AWS
aws.amazon.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
Scanned Aug 28, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
Tuning uses a private model copy; customer data is not shared with model providers and is not used to improve the base models.
“When you tune a foundation model, we base it on a private copy of that model. This means your data is not shared with model providers, and is not used to improve the base models.”
“We do not access or use your content for any purpose without your agreement. We do not use your content or derive information from it for marketing or advertising purposes.”
“With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.”
✓How long do they keep your data?Clear
The service terms commit to deleting customer content following account closure, per service documentation.
“Following closure of your AWS account, we will delete Your Content in accordance with the technical documentation applicable to the Services.”
✓Who else can access your data?Clear
AWS commits to not disclosing customer content unless legally compelled, redirecting government demands to the customer where possible.
“We will not disclose customer content (see How does AWS classify customer information? below) unless we're required to do so to comply with the law or a valid and binding order of a government body. If a governmental body sends AWS a demand for your customer content, we will attempt to redirect the governmental body to request that data directly”
“AWS will update this page at least 30 days before engaging a new sub-processor, and if you subscribe for updates , AWS will notify you by email of changes to this page.”
“Which FMs are available in Amazon Bedrock? Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today. This includes models from: AI21 Labs Amazon Anthropic Cohere DeepSeek Luma AI Meta Mistral AI OpenAI poolsid e (coming soon) Stability AI TwelveLabs Writer”
!Where is your data processed?Ask the vendor
The customer chooses storage Region(s); AWS will not move or replicate content outside them without agreement.
Confirm in writing: Ask the vendor to state this in writing before signing.
“You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.”
“To improve performance, such services may use cross-region inference, using the optimal AWS Region to process your Content when running model inference.”
“Customized FMs remain in the Region where the API call is processed.”
✓What happens in a security incident?Clear
AWS documents a security incident monitoring and data breach notification process, committing to notify customers of breaches of AWS security without undue delay per the DPA.
“AWS has a security incident monitoring and data breach notification process in place and will notify customers of breaches of AWS’s security without undue delay and in accordance with the AWS DPA.”
Key findingsclick a row for the evidence
✓Customer-content commitments are unusually concreteStrong
AWS commits in plain terms to Region choice with no movement without agreement, no access or use of content without agreement, deletion on account closure, and legal-demand redirection with notice.
These are contractual-grade answers to the questions buyers usually have to negotiate for.
“You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.”
“We do not access or use your content for any purpose without your agreement. We do not use your content or derive information from it for marketing or advertising purposes.”
“We will not disclose customer content (see How does AWS classify customer information? below) unless we're required to do so to comply with the law or a valid and binding order of a government body. If a governmental body sends AWS a demand for your customer content, we will attempt to redirect the governmental body to request that data directly”
“Following closure of your AWS account, we will delete Your Content in accordance with the technical documentation applicable to the Services.”
✓Breach notification is committed, not aspirationalStrong
The GDPR centre documents a monitoring and breach-notification process with a without-undue-delay commitment anchored to the DPA.
Incident-response commitments anchored in the DPA are enforceable, unlike page prose.
“AWS has a security incident monitoring and data breach notification process in place and will notify customers of breaches of AWS’s security without undue delay and in accordance with the AWS DPA.”
!Organisation-level AI change management is not evidencedGap
Model lifecycle commitments exist at the Bedrock product level, but no organisation-wide AI change or deprecation policy was found in the collected sources.
AWS ships AI features across dozens of services under the service terms; buyers of non-Bedrock AI features have no equivalent lifecycle commitment.
Question for vendor: Do the Bedrock model-lifecycle commitments (12-month availability, 6-month legacy notice) extend to AI features embedded in other AWS services?
“Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex,”
!Cross-region inference qualifies the residency storyGap
Region-of-use storage commitments coexist with service terms allowing cross-region inference for Bedrock-powered features.
A buyer relying on strict residency needs to confirm cross-region inference is disabled or acceptable for their deployment.
Question for vendor: Which generative AI features use cross-region inference by default, and how is it disabled?
“You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.”
“To improve performance, such services may use cross-region inference, using the optimal AWS Region to process your Content when running model inference.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score80
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“AWS defines responsible AI using a core set of dimensions that we assess and update over time as AI technology evolves.”
“G7 AI Hiroshima Process Code of Conduct , AI Safety Summit in the UK , and support for ISO 42001 , a new foundational standard to advance responsible AI.”
“Cloud Infrastructure Services Providers in Europe (CISPE) Data Protection Code of Conduct Public Register includes a list of adherent AWS services.”
Governance & accountability: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI system15% of the score27
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“With Amazon Bedrock, you have full control over the data you use to customize the foundation models for your generative AI applications.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“Amazon SageMaker Clarify helps you mitigate bias by detecting potential bias during data preparation, after model training, and in your deployed model by examining specific attributes.”
“Amazon Bedrock Guardrails helps you implement safeguards customized to your application requirements and responsible AI policies. With industry-leading safety protections that block up to 88% of harmful content and deliver auditable, mathematically verifiable explanations for validation decisions with 99% accuracy,”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
Change management: not publicly evidenced.
Model10% of the score40
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Which FMs are available in Amazon Bedrock? Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today. This includes models from: AI21 Labs Amazon Anthropic Cohere DeepSeek Luma AI Meta Mistral AI OpenAI poolsid e (coming soon) Stability AI TwelveLabs Writer”
Customer data15% of the score85
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“When you tune a foundation model, we base it on a private copy of that model. This means your data is not shared with model providers, and is not used to improve the base models.”
“You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.”
“We do not access or use your content for any purpose without your agreement. We do not use your content or derive information from it for marketing or advertising purposes.”
“We offer customers strong encryption for customer data in transit or at rest, and we provide customers with the option to manage their own encryption keys.”
“To improve performance, such services may use cross-region inference, using the optimal AWS Region to process your Content when running model inference.”
“Following closure of your AWS account, we will delete Your Content in accordance with the technical documentation applicable to the Services.”
“With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.”
“Customized FMs remain in the Region where the API call is processed.”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the score60
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“Yes, AWS may use three types of sub-processors: (1) AWS entities that provide the infrastructure on which the AWS services run; (2) AWS entities that support specific AWS services which may require these entities to process customer data;”
“AWS will update this page at least 30 days before engaging a new sub-processor, and if you subscribe for updates , AWS will notify you by email of changes to this page.”
Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.
Security foundation15% of the score65
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“AWS has a security incident monitoring and data breach notification process in place and will notify customers of breaches of AWS’s security without undue delay and in accordance with the AWS DPA.”
Independent assurance evidence10% of the score100
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“AWS supports 143 security standards and compliance certifications, including PCI-DSS, HIPAA/HITECH, FedRAMP, GDPR, FIPS 140-3, and NIST 800-171, helping customers satisfy compliance requirements around the globe.”
“Get on-demand access to AWS and ISV security and compliance reports by using AWS Artifact. Find auditor-issued reports, certifications, accreditations, and other third-party attestations of AWS in a comprehensive resource.”
“AWS complies with ISO 27018, a code of practice that focuses on protection of personal data in the cloud. It extends ISO information security standard 27001 to cover the regulatory requirements for the protection of personally identifiable information (PII) or personal data for the public cloud computing environment”
“AWS publishes a SOC 2 Type II report, developed by the American Institute of CPAs (AICPA), which establishes criteria for evaluating controls related to how personal data is collected, used, retained, disclosed, and disposed to meet the entity’s objectives. The AWS SOC 2 Type II report provides third-party attestation of our systems and the suitability of the design of our controls.”
“Amazon Bedrock is included in the scope of the SOC 1, 2, 3 reports,”
“Examples of this include AWS' ISO 27001 , 27017, and 27018 compliance.”
“Amazon Bedrock is CSA Security Trust Assurance and Risk (STAR) Level 2 certified, which validates the use of best practices and the security posture of AWS cloud offerings.”
Document held and reviewed by TrustyCyber — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“We will not disclose customer content (see How does AWS classify customer information? below) unless we're required to do so to comply with the law or a valid and binding order of a government body. If a governmental body sends AWS a demand for your customer content, we will attempt to redirect the governmental body to request that data directly”
“continue to rely on the SCCs for any transfer of customer data outside the EEA in compliance with GDPR.”
“Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex,”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 65 → up to 82 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 12 — registry checks and verification ladders, click to view
ISO/IEC 27001:2022, Ernst & Young CertifyPoint B.V., RvA-accredited (Dutch Accreditation Council), certificate 2013-009, Active, record last updated 16 Jan 2026. SCOPE LIMITATION OF THE RECORD: the registry entry lists only the certified entity and its Seattle main site, with no scope-of-registration statement and no technical sectors - it does not state which AWS services the ISMS covers. Ask AWS for the certificate with its scope statement to establish service coverage.
Checked against IAF CertSearch, Aug 24, 2026: Verified on the registry
Checked against ISO/IEC 27017:2015 certificate 2015-015 (AWS Artifact download supplied by Robbo 2026-08-28), Aug 28, 2026: Verified on the registry
Checked against ISO/IEC 27018:2019 certificate held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry
Published report; access via AWS Artifact.
Checked against SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry
Stated on the Bedrock FAQ.
Checked against CSA STAR Registry, Aug 28, 2026: Verified on the registry
Named in the 143-programme list; per-service scope on the services-in-scope page.
Checked against AWS FedRAMP Customer Package held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry
Named in the 143-programme list.
Checked against Visa Global Registry of Service Providers, Aug 24, 2026: Verified on the registry
Checked against ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (AWS Artifact), Aug 24, 2026: Verified on the registry
ISO/IEC 27701:2019 (privacy information management system), Ernst & Young CertifyPoint B.V., RvA-accredited, certificate 2021-035, Active, record last updated 16 Jan 2026. SCOPE LIMITATION OF THE RECORD: entity and Seattle main site only, no scope-of-registration statement and no technical sectors - the record does not state which AWS services the PIMS covers, nor whether AWS is certified as PII controller or processor.
Checked against IAF CertSearch, Aug 24, 2026: Verified on the registry
SOC 2 Type 2 by EY (Ernst & Young), period 1 Apr 2025 - 31 Mar 2026 (current), trust services criteria security, availability, confidentiality and privacy. Type 2: controls both suitably designed AND operating effectively across the period. The report defines a specific in-scope AWS service list and does not blanket every AWS service - check that list before relying on it for a particular service. Vault: Gated/AWS/2026-03_aws-soc2-type2-ey.pdf.
Checked against SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact), Aug 24, 2026: Verified on the registry
CSA STAR Registry: AWS holds both STAR Level 1 (CAIQ self-assessment v4.0.2) and STAR Level 2 (STAR Certification v4.0, a third-party certification combining ISO/IEC 27001 with the CSA Cloud Controls Matrix). Level 2 created or renewed 20 April 2026; listed since 11 June 2020.
Checked against CSA STAR Registry, Aug 24, 2026: Verified on the registry
Checked against Data Privacy Framework (dataprivacyframework.gov), Aug 28, 2026: Verified on the registry
Sources 24 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
Want to go further?
This scan assesses AWS at an organisational level. Assurance can vary significantly between products, models and agents — enter the product you’re evaluating to run a deeper AI System Assurance Scan.
Scan a specific product →This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
