Amazon Bedrock
aws.amazon.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Aug 28, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
“Amazon Bedrock gives you explicit control over whether your prompts and outputs are retained from your inference requests. You can configure data retention at the account or project level, and the setting is enforced consistently across the Messages, Chat Completions, and Responses APIs.”
“Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider.”
“user prompts and completions are shared with Anthropic and retained for up to 30 days for trust and safety purposes.”
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
Bedrock states customer content is not used to improve the base models and is not shared with any model providers.
“With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.”
“When you tune a foundation model, we base it on a private copy of that model. This means your data is not shared with model providers, and is not used to improve the base models.”
“No, prompts that AWS customers enter into Amazon FMs and outputs produced in response to Amazon FM prompts are not used to train the underlying Amazon FMs, unless a customer consents.”
“We do not access or use your content for any purpose without your agreement. We do not use your content or derive information from it for marketing or advertising purposes.”
!How long do they keep your data?Ask the vendor
Bedrock documents explicit, customer-controlled retention modes: default (provider does not receive data; AWS may retain for safety), provider_data_share (opt-in sharing required for certain models), and none (zero data retention — nothing written to durable storage or shared with the model provider).
Requires written confirmation — see Before you sign ↓
“Amazon Bedrock gives you explicit control over whether your prompts and outputs are retained from your inference requests. You can configure data retention at the account or project level, and the setting is enforced consistently across the Messages, Chat Completions, and Responses APIs.”
“Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider.”
“user prompts and completions are shared with Anthropic and retained for up to 30 days for trust and safety purposes.”
!Who else can access your data?Ask the vendor
Bedrock publicly names its foundation model providers, including AI21 Labs, Amazon, Anthropic, Cohere, DeepSeek, Luma AI, Meta, Mistral AI, OpenAI, Stability AI, TwelveLabs and Writer, with a per-model reference in the documentation.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Which FMs are available in Amazon Bedrock? Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today. This includes models from: AI21 Labs Amazon Anthropic Cohere DeepSeek Luma AI Meta Mistral AI OpenAI poolsid e (coming soon) Stability AI TwelveLabs Writer”
“This mode allows Amazon Bedrock to retain and share your inference data with model providers per their requirements. It is required for access to certain models. See Amazon Bedrock abuse detection”
“AWS will update this page at least 30 days before engaging a new sub-processor, and if you subscribe for updates , AWS will notify you by email of changes to this page.”
“Are user inputs and model outputs made available to third-party model providers? No. Users' inputs and model outputs are not shared with any model providers.”
“We will not disclose customer content (see How does AWS classify customer information? below) unless we're required to do so to comply with the law or a valid and binding order of a government body. If a governmental body sends AWS a demand for your customer content, we will attempt to redirect the governmental body to request that data directly from you. If compelled to disclose your customer content to a government body, we will give you reasonable notice of the demand”
!Where is your data processed?Ask the vendor
AWS states customers can use all AWS services to process personal data in compliance with the GDPR, with a published GDPR centre and Data Processing Addendum.
Confirm in writing: Ask the vendor to state this in writing before signing.
“AWS customers can use all AWS services to process personal data (as defined in the GDPR) that is uploaded to the AWS services under their AWS accounts (customer data) in compliance with the GDPR”
“Any customer content processed by Amazon Bedrock is encrypted and stored at rest in the AWS Region where you are using Amazon Bedrock.”
“You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.”
“If cross-region inference is enabled for these models, retained inputs and outputs are stored in destination regions”
!What happens in a security incident?Ask the vendor
AWS states it is responsible for incident response for the Bedrock service itself, with the customer responsible for incident response on their side of the shared responsibility model.
Confirm in writing: Ask the vendor to state this in writing before signing.
“AWS is responsible for any incident response with respect to the Amazon Bedrock service itself. Also, as an AWS customer, you share a responsibility for maintaining security in the cloud. This means that you control the security you choose to implement from the AWS tools and features you have access to. In addition, you’re responsible for incident response on your side of the shared responsibility model.”
Key findingsclick a row for the evidence
✓Product-level data-use commitments are explicit and detailedStrong
Bedrock documents, at product level, that customer content is not used to improve base models and is not shared with model providers, and publishes customer-controlled retention modes including guaranteed zero data retention.
These are the two questions AI buyers open with; Bedrock answers both in its own documentation rather than leaving them to contract negotiation.
“With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.”
“Amazon Bedrock gives you explicit control over whether your prompts and outputs are retained from your inference requests. You can configure data retention at the account or project level, and the setting is enforced consistently across the Messages, Chat Completions, and Responses APIs.”
“Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider.”
!provider_data_share mode is required for some modelsGap
A documented opt-in mode retains and shares inference data with model providers per their requirements and is required for access to certain models; which models require it is not stated on the retention page itself.
A buyer standardising on zero retention may find specific models unavailable, or may enable sharing without realising which providers receive data.
Question for vendor: Which Bedrock models require provider_data_share or data retention, and what do those providers receive?
“This mode allows Amazon Bedrock to retain and share your inference data with model providers per their requirements. It is required for access to certain models. See Amazon Bedrock abuse detection”
!ISO/IEC 42001 held at organisation level; certificate scope sits behind AWS ArtifactGap
AWS holds ISO/IEC 42001:2023 via Schellman, but the FAQ page defers the in-scope service list to the certificate in AWS Artifact, which requires an AWS account to access.
Whether Bedrock itself is in the certified scope is the load-bearing fact for an AI assurance decision; it is verifiable, but not on the public page.
“Achieving ISO/IEC 42001 certification means that an independent third party has validated that AWS is taking proactive steps to manage risks and opportunities associated with AI development, deployment, and operation. This independent validation enables our customers to gain further assurances around AWS’s commitment to responsible AI and their ability to build and operate AI applications responsibly using AWS Services.”
“Bedrock is in scope for common compliance standards including ISO, SOC, CSA STAR Level 2, is HIPAA eligible, and customers can use Bedrock in compliance with the GDPR. Amazon Bedrock is a FedRAMP High authorized service in the AWS GovCloud (US-West) Region.”
!Multi-provider model supply chain with divergent lifecycle and data termsGap
Bedrock aggregates a dozen named model providers; lifecycle dates may differ from providers’ own published dates, and retention requirements vary by model.
The provider behind each model determines the real data-handling and deprecation terms a deployment inherits; per-model confirmation is needed rather than relying on the platform-level statement alone.
Question for vendor: For the specific models in use, confirm the applicable retention mode, provider data access, and lifecycle dates.
“Which FMs are available in Amazon Bedrock? Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today. This includes models from: AI21 Labs Amazon Anthropic Cohere DeepSeek Luma AI Meta Mistral AI OpenAI poolsid e (coming soon) Stability AI TwelveLabs Writer”
“Once a model launches on Amazon Bedrock, it will remain on Amazon Bedrock for at least 12 months before the EOL date.”
“This mode allows Amazon Bedrock to retain and share your inference data with model providers per their requirements. It is required for access to certain models. See Amazon Bedrock abuse detection”
✓Per-model retention exceptions are named, not hiddenStrong
The retention documentation names the exact models whose use shares prompts and completions with the model provider (Claude Mythos 5 / Claude Fable 5, retained up to 30 days by Anthropic for trust and safety) instead of burying the exception in generic terms.
Buyers can make a per-model decision with the specific data flow in front of them — the disclosure quality this scanner exists to reward.
“user prompts and completions are shared with Anthropic and retained for up to 30 days for trust and safety purposes.”
“For a full list of models requiring data retention, see Amazon Bedrock abuse detection”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the score80
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“AWS defines responsible AI using a core set of dimensions that we assess and update over time as AI technology evolves.”
“The new AWS Well-Architected Responsible AI Lens provides best practices and practical guidance to help you address these considerations across design, development, and operation. Apply this guidance to make informed decisions that balance your business and technical requirements and help speed up the deployment of trusted AI systems.”
“Model invocation logging is disabled by default. After model invocation logging is enabled, logs are stored until the logging configuration is deleted.”
Governance & accountability: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI system15% of the score53
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today.”
“Which FMs are available in Amazon Bedrock? Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today. This includes models from: AI21 Labs Amazon Anthropic Cohere DeepSeek Luma AI Meta Mistral AI OpenAI poolsid e (coming soon) Stability AI TwelveLabs Writer”
“you can experiment with a variety of top FMs, customize them privately with your data using techniques such as fine-tuning and retrieval-augmented generation (RAG), and create managed agents that execute complex business tasks—from booking travel and processing insurance claims to creating ad campaigns and managing inventory—all without writing any code.”
“Amazon Bedrock Agents use the reasoning of FMs, APIs, and data to break down user requests, gather relevant information, and efficiently perform tasks.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“Amazon Bedrock Guardrails provides configurable safeguards to help you build safe generative AI applications. With comprehensive safety and privacy controls across foundation models (FMs), Amazon Bedrock Guardrails offers a consistent user experience to help detect and filter undesirable content and protect sensitive information that might be present in user inputs or model responses”
“AI Service Cards are a resource to enhance transparency by providing you with a single place to find information on the intended use cases and limitations, responsible AI design choices, and performance optimization best practices for our AI services and models.”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“Once a model launches on Amazon Bedrock, it will remain on Amazon Bedrock for at least 12 months before the EOL date.”
“We will notify you when a model provider moves a model to the Legacy state. A model will be in the Legacy state for at least 6 months before the EOL date”
AI system description: vendor-evidenced, not yet independently corroborated.
Change management: vendor-evidenced, not yet independently corroborated.
Model10% of the score60
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Which FMs are available in Amazon Bedrock? Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today. This includes models from: AI21 Labs Amazon Anthropic Cohere DeepSeek Luma AI Meta Mistral AI OpenAI poolsid e (coming soon) Stability AI TwelveLabs Writer”
“This mode allows Amazon Bedrock to retain and share your inference data with model providers per their requirements. It is required for access to certain models. See Amazon Bedrock abuse detection”
“For a full list of models requiring data retention, see Amazon Bedrock abuse detection”
Model provider transparency: vendor-evidenced, not yet independently corroborated.
Customer data15% of the score80
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.”
“When you tune a foundation model, we base it on a private copy of that model. This means your data is not shared with model providers, and is not used to improve the base models.”
“Amazon Bedrock gives you explicit control over whether your prompts and outputs are retained from your inference requests. You can configure data retention at the account or project level, and the setting is enforced consistently across the Messages, Chat Completions, and Responses APIs.”
“Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider.”
“No, prompts that AWS customers enter into Amazon FMs and outputs produced in response to Amazon FM prompts are not used to train the underlying Amazon FMs, unless a customer consents.”
“Any customer content processed by Amazon Bedrock is encrypted and stored at rest in the AWS Region where you are using Amazon Bedrock.”
“Are user inputs and model outputs made available to third-party model providers? No. Users' inputs and model outputs are not shared with any model providers.”
“Your data in Amazon Bedrock is always encrypted in transit and at rest, and you can optionally encrypt the data using your own keys. You can use AWS PrivateLink with Amazon Bedrock to establish private connectivity between your FMs and your Amazon Virtual Private Cloud (Amazon VPC) without exposing your traffic to the Internet.”
“You choose the AWS Region(s) in which your content is stored. You can replicate and back up your content in more than one AWS Region. We will not move or replicate your content outside of your chosen AWS Region(s) without your agreement.”
“We do not access or use your content for any purpose without your agreement. We do not use your content or derive information from it for marketing or advertising purposes.”
“user prompts and completions are shared with Anthropic and retained for up to 30 days for trust and safety purposes.”
“If cross-region inference is enabled for these models, retained inputs and outputs are stored in destination regions”
“Amazon Bedrock is in scope for common compliance standards such as Fedramp Moderate, Service and Organization Control (SOC),”
“This mode allows Amazon Bedrock to retain and share your inference data with model providers per their requirements. It is required for access to certain models. See Amazon Bedrock abuse detection”
Customer data treatment: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
AI supply chain10% of the score60
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“AWS will update this page at least 30 days before engaging a new sub-processor, and if you subscribe for updates , AWS will notify you by email of changes to this page.”
“Which FMs are available in Amazon Bedrock? Amazon Bedrock customers can choose from some of the most cutting-edge FMs available today. This includes models from: AI21 Labs Amazon Anthropic Cohere DeepSeek Luma AI Meta Mistral AI OpenAI poolsid e (coming soon) Stability AI TwelveLabs Writer”
“there are four types of sub-processors: AWS entities that provide the infrastructure on which the AWS services run; AWS entities that support specific AWS services which may require these entities to process Customer Data;”
Subprocessors & supply chain: vendor-evidenced, not yet independently corroborated.
Security foundation15% of the score65
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“AWS is responsible for any incident response with respect to the Amazon Bedrock service itself. Also, as an AWS customer, you share a responsibility for maintaining security in the cloud. This means that you control the security you choose to implement from the AWS tools and features you have access to. In addition, you’re responsible for incident response on your side of the shared responsibility model.”
“Amazon GuardDuty is able to detect suspicious activity in Amazon Bedrock APIs, such as a user logging in from a new location and using Amazon Bedrock APIs to remove Amazon Bedrock Guardrails, or change the Amazon S3 bucket set for model training data.”
“Reporting of Violations To report any violation of this Policy, please follow our abuse reporting process”
Independent assurance evidence10% of the score100
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“Achieving ISO/IEC 42001 certification means that an independent third party has validated that AWS is taking proactive steps to manage risks and opportunities associated with AI development, deployment, and operation. This independent validation enables our customers to gain further assurances around AWS’s commitment to responsible AI and their ability to build and operate AI applications responsibly using AWS Services.”
“Bedrock is in scope for common compliance standards including ISO, SOC, CSA STAR Level 2, is HIPAA eligible, and customers can use Bedrock in compliance with the GDPR. Amazon Bedrock is a FedRAMP High authorized service in the AWS GovCloud (US-West) Region.”
“ISO 42001 ISO 45001 ISO 50001 ISO 9001 KY3P PCI 3DS PCI DSS PCI P2PE PCI PIN ProcessUnity SOC 1 SOC 2 SOC 3”
Read from the registry record above — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Document held and reviewed by TrustyCyber — cited, not reproduced.
Independent assurance: vendor-evidenced, not yet independently corroborated.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“AWS customers can use all AWS services to process personal data (as defined in the GDPR) that is uploaded to the AWS services under their AWS accounts (customer data) in compliance with the GDPR”
“We will not disclose customer content (see How does AWS classify customer information? below) unless we're required to do so to comply with the law or a valid and binding order of a government body. If a governmental body sends AWS a demand for your customer content, we will attempt to redirect the governmental body to request that data directly from you. If compelled to disclose your customer content to a government body, we will give you reasonable notice of the demand”
“Is AWS a data processor or a data controller under the GDPR? AWS acts as both a data processor and a data controller under the GDPR.”
“Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex,”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 70 → up to 84 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 7 — registry checks and verification ladders, click to view
Issued by Schellman Compliance (ANAB-accredited); in-scope services listed on the certificate in AWS Artifact, not on the public page.
Checked against ISO/IEC 42001:2023 certificate held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry
Bedrock security page cites "ISO" programmes generically; the certified standard list and Bedrock inclusion live on the ISO-certified services page and certificates.
Checked against ISO/IEC 27001:2022 certificate held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry
Cited generically as "SOC" on the Bedrock security page; report access is via AWS Artifact.
Checked against SOC 2 Type 2 report held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry
Named at Level 2 on the Bedrock security page.
Checked against CSA STAR Certification (CCM v4.0) certificate held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry
Bedrock stated as FedRAMP High authorized in AWS GovCloud (US-West).
Checked against AWS FedRAMP Customer Package held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Aug 28, 2026: Verified on the registry
EY CertifyPoint 2015-016, re-issued 20 May 2026.
Checked against ISO/IEC 27018:2019 certificate held in the TrustyCyber vault (AWS Artifact), Aug 28, 2026: Verified on the registry
Sources 48 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
