Amazon Q
aws.amazon.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No formal subprocessor register disclosed
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Aug 31, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.
What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
✓Will they train on your data?Clear
The consent permitting AWS to use AI Content to develop and improve its services covers a closed list of named services that does not include Amazon Q, and the clause states expressly that it applies to no AI Service outside that list.
“50.3. You agree and instruct that for Amazon CodeGuru Profiler, Amazon Comprehend, Amazon Lex, Amazon Polly, Amazon Rekognition, Amazon Textract, Amazon Transcribe, Amazon Translate, AWS Transform, AWS FinOps Agent (Preview), Kiro Free Tier, and Kiro individual subscribers (as described here ): (a) we may use and store AI Content that is processed by each of the foregoing AI Services to develop and improve the applicable AI Service and its underlying technologies; (b) we may use and store AI Content that is not personal data to develop and improve AWS and affiliate machine-learning and artificial-intelligence technologies; and (c) solely in connection with the development and improvement described in clauses (a) and (b), we may store such AI Content in an AWS region outside of the AWS region where you are using such AI Service. This Section does not apply to Amazon Comprehend Medical, Amazon Transcribe Medical, AWS HealthScribe, Amazon Comprehend Detect PII or any AI Service that is not listed in the first sentence of this Section 50.3.”
!How long do they keep your data?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!Who else can access your data?Ask the vendor
The Service Terms state that the generative AI features in a named list of services, Amazon Q among them, are powered by Amazon Bedrock.
Requires written confirmation — see Before you sign ↓
“Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex, Amazon OpenSearch Service, Amazon Personalize, Amazon Q, AWS Entity Resolution, AWS Transform, AWS AppFabric, AWS HealthScribe, AWS Resilience Hub, AWS App Studio, Kiro, Amazon SageMaker Data Agent, the model customization agent in SageMaker AI, Amazon Quick, AWS DevOps Agent, AWS Continuum (including features previously named AWS Security Agent), AWS FinOps Agent (Preview), Amazon WorkSpaces, AWS Deadline Cloud, and Amazon GuardDuty.”
“This page provides information about the sub-processors that AWS has engaged in accordance with the AWS Data Processing Addendum (AWS DPA) to provide processing activities on Customer Data (as defined in the AWS DPA) on behalf of customers.”
!Where is your data processed?Ask the vendor
Services carrying Bedrock-powered generative AI features may use cross-region inference, processing customer content in whichever AWS Region is optimal rather than only the customer's chosen one.
Confirm in writing: Ask the vendor to state this in writing before signing.
“To improve performance, such services may use cross-region inference, using the optimal AWS Region to process your Content when running model inference. See the applicable service documentation for more details.”
!What happens in a security incident?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
Confirm in writing: Ask the vendor to state this in writing before signing.
Key findingsclick a row for the evidence
✓Amazon Q is excluded by name from AWS's train-on-your-content clauseStrong
Amazon Q is a defined AI Service, but the consent letting AWS use AI Content to develop and improve its services covers a closed list that does not include it — and the clause says it applies to nothing outside that list.
This is a contractual exclusion a buyer can point at rather than a marketing assurance that can be reworded. The same document that grants the training right for other services withholds it here.
““AI Services” means, collectively, Amazon Bedrock, Amazon CodeGuru Profiler, Amazon CodeGuru Reviewer, Amazon Foundation Models (Amazon Nova and Titan models), Amazon Nova Act, Amazon Nova Forge, Amazon Comprehend, Amazon Comprehend Medical, Amazon DevOps Guru, Amazon Forecast, AWS HealthLake, Amazon Kendra, Amazon Lex, Amazon Lookout for Metrics, Amazon Personalize, Amazon Polly, Amazon Q, AWS Transform, Amazon Rekognition, Amazon Textract, Amazon Transcribe, Amazon Transcribe Medical, Amazon Translate, AWS HealthOmics, AWS HealthImaging, AWS HealthScribe, AWS App Studio, Kiro, Amazon Quick, AWS Elemental Inference, AWS DevOps Agent, AWS Continuum (including features previously named AWS Security Agent), AWS FinOps Agent (Preview), the model customization agent in SageMaker AI, and AWS IoT SiteWise Scenario Discovery.”
“50.3. You agree and instruct that for Amazon CodeGuru Profiler, Amazon Comprehend, Amazon Lex, Amazon Polly, Amazon Rekognition, Amazon Textract, Amazon Transcribe, Amazon Translate, AWS Transform, AWS FinOps Agent (Preview), Kiro Free Tier, and Kiro individual subscribers (as described here ): (a) we may use and store AI Content that is processed by each of the foregoing AI Services to develop and improve the applicable AI Service and its underlying technologies; (b) we may use and store AI Content that is not personal data to develop and improve AWS and affiliate machine-learning and artificial-intelligence technologies; and (c) solely in connection with the development and improvement described in clauses (a) and (b), we may store such AI Content in an AWS region outside of the AWS region where you are using such AI Service. This Section does not apply to Amazon Comprehend Medical, Amazon Transcribe Medical, AWS HealthScribe, Amazon Comprehend Detect PII or any AI Service that is not listed in the first sentence of this Section 50.3.”
✓IP indemnity covers generated output, but not on the free tierStrong
AWS will defend customers against third-party IP claims arising from Amazon Q's generated output and pay any adverse judgment. The list explicitly excludes the Amazon Q Developer Free Tier.
IP indemnity is one of the first questions asked of any coding assistant, and few vendors offer it. The free-tier carve-out matters operationally: developers trialling the free tier are outside the protection their organisation may believe it has.
Question for vendor: Which of our developers are on the Amazon Q Developer Free Tier, and are they therefore outside the IP indemnity?
“50.10.1. Subject to the limitations in this Section 50.10, AWS will defend you and your employees, officers, and directors against any third-party claim alleging that the Generative AI Output generated by an Indemnified Generative AI Service infringes or misappropriates that third party’s intellectual property rights, and will pay the amount of any adverse final judgment or settlement.”
““Indemnified Generative AI Services” means, collectively, generally available features of Amazon Nova Micro, Amazon Nova Lite, Amazon Nova Pro, Amazon Nova Premier, Amazon Nova Canvas, Amazon Nova Reel , Amazon Nova Forge Models (as defined below) , Amazon Nova Sonic, Amazon Nova 2 Omni, Amazon Nova Act, Amazon Titan Text Express, Amazon Titan Text Lite, Amazon Nova Multimodal Embeddings, Amazon Titan Text Premier, Amazon Titan Text Embeddings, Amazon Titan Multimodal Embeddings, Amazon Titan Image Generator, AWS HealthScribe, Amazon Personalize, Amazon Q (excluding Amazon Q Developer Free Tier), AWS Transform, Amazon Bio Discovery (excluding Amazon Bio Discovery Academic Tier), Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, Amazon Lex, Kiro (excluding Kiro Free Tier), AWS DevOps Agent, AWS Security Agent, and Amazon Quick.”
!Prompts may be processed outside the chosen RegionGap
Bedrock-powered generative AI features, which the terms state include Amazon Q, may use cross-region inference and process content in whichever AWS Region is optimal.
An organisation that chose an AWS Region for data-residency reasons can have AI inference leave it. For Australian buyers with sovereignty commitments this is the clause to check before deployment, and it is not surfaced in the product marketing.
Question for vendor: Which Regions can Amazon Q inference reach for our account, and can cross-region inference be disabled?
“Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex, Amazon OpenSearch Service, Amazon Personalize, Amazon Q, AWS Entity Resolution, AWS Transform, AWS AppFabric, AWS HealthScribe, AWS Resilience Hub, AWS App Studio, Kiro, Amazon SageMaker Data Agent, the model customization agent in SageMaker AI, Amazon Quick, AWS DevOps Agent, AWS Continuum (including features previously named AWS Security Agent), AWS FinOps Agent (Preview), Amazon WorkSpaces, AWS Deadline Cloud, and Amazon GuardDuty.”
“To improve performance, such services may use cross-region inference, using the optimal AWS Region to process your Content when running model inference. See the applicable service documentation for more details.”
✓The model supply chain is Bedrock, stated in the termsStrong
Amazon Q is named among the services whose generative AI features are powered by Amazon Bedrock, so its inference platform is AWS's own rather than an undisclosed third party.
A buyer can inherit the assurance already established for Bedrock instead of assessing an opaque dependency, and knows which abuse-detection and model-access controls apply.
“Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex, Amazon OpenSearch Service, Amazon Personalize, Amazon Q, AWS Entity Resolution, AWS Transform, AWS AppFabric, AWS HealthScribe, AWS Resilience Hub, AWS App Studio, Kiro, Amazon SageMaker Data Agent, the model customization agent in SageMaker AI, Amazon Quick, AWS DevOps Agent, AWS Continuum (including features previously named AWS Security Agent), AWS FinOps Agent (Preview), Amazon WorkSpaces, AWS Deadline Cloud, and Amazon GuardDuty.”
!A dated deprecation signal exists for the IDE pluginsGap
AWS has announced that support for the Amazon Q Developer IDE plugins ends on 30 April 2027.
Published end-of-support dates are what let an organisation plan migrations rather than discover them. It is a positive change-management signal, and a date to carry into any deployment plan.
“On April 30, 2027, AWS will discontinue support for Amazon Q Developer IDE plugins.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the scoreorganisation-level evidence0
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
Governance & accountability: not publicly evidenced.
AI system15% of the score33
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“Amazon Q Business makes generative AI securely accessible to everyone in your organization. Leveraging your own company's content, data, and systems, Amazon Q Business makes it easier to get you fast, relevant answers to pressing questions, solve problems, generate content, and take actions on your behalf.”
“Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex, Amazon OpenSearch Service, Amazon Personalize, Amazon Q, AWS Entity Resolution, AWS Transform, AWS AppFabric, AWS HealthScribe, AWS Resilience Hub, AWS App Studio, Kiro, Amazon SageMaker Data Agent, the model customization agent in SageMaker AI, Amazon Quick, AWS DevOps Agent, AWS Continuum (including features previously named AWS Security Agent), AWS FinOps Agent (Preview), Amazon WorkSpaces, AWS Deadline Cloud, and Amazon GuardDuty.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“On April 30, 2027, AWS will discontinue support for Amazon Q Developer IDE plugins.”
AI system description: vendor-evidenced, not yet independently corroborated.
Testing & evaluation: not publicly evidenced.
Model10% of the score40
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“Certain Services may incorporate generative AI features, powered by Amazon Bedrock, that enable you to use prompts to generate output, including: Amazon Bio Discovery, Amazon CloudWatch, Amazon CodeCatalyst, Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, AWS Database Migration Service, Amazon DataZone, Amazon Lex, Amazon OpenSearch Service, Amazon Personalize, Amazon Q, AWS Entity Resolution, AWS Transform, AWS AppFabric, AWS HealthScribe, AWS Resilience Hub, AWS App Studio, Kiro, Amazon SageMaker Data Agent, the model customization agent in SageMaker AI, Amazon Quick, AWS DevOps Agent, AWS Continuum (including features previously named AWS Security Agent), AWS FinOps Agent (Preview), Amazon WorkSpaces, AWS Deadline Cloud, and Amazon GuardDuty.”
Customer data15% of the score40
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
““AI Services” means, collectively, Amazon Bedrock, Amazon CodeGuru Profiler, Amazon CodeGuru Reviewer, Amazon Foundation Models (Amazon Nova and Titan models), Amazon Nova Act, Amazon Nova Forge, Amazon Comprehend, Amazon Comprehend Medical, Amazon DevOps Guru, Amazon Forecast, AWS HealthLake, Amazon Kendra, Amazon Lex, Amazon Lookout for Metrics, Amazon Personalize, Amazon Polly, Amazon Q, AWS Transform, Amazon Rekognition, Amazon Textract, Amazon Transcribe, Amazon Transcribe Medical, Amazon Translate, AWS HealthOmics, AWS HealthImaging, AWS HealthScribe, AWS App Studio, Kiro, Amazon Quick, AWS Elemental Inference, AWS DevOps Agent, AWS Continuum (including features previously named AWS Security Agent), AWS FinOps Agent (Preview), the model customization agent in SageMaker AI, and AWS IoT SiteWise Scenario Discovery.”
“50.3. You agree and instruct that for Amazon CodeGuru Profiler, Amazon Comprehend, Amazon Lex, Amazon Polly, Amazon Rekognition, Amazon Textract, Amazon Transcribe, Amazon Translate, AWS Transform, AWS FinOps Agent (Preview), Kiro Free Tier, and Kiro individual subscribers (as described here ): (a) we may use and store AI Content that is processed by each of the foregoing AI Services to develop and improve the applicable AI Service and its underlying technologies; (b) we may use and store AI Content that is not personal data to develop and improve AWS and affiliate machine-learning and artificial-intelligence technologies; and (c) solely in connection with the development and improvement described in clauses (a) and (b), we may store such AI Content in an AWS region outside of the AWS region where you are using such AI Service. This Section does not apply to Amazon Comprehend Medical, Amazon Transcribe Medical, AWS HealthScribe, Amazon Comprehend Detect PII or any AI Service that is not listed in the first sentence of this Section 50.3.”
“To improve performance, such services may use cross-region inference, using the optimal AWS Region to process your Content when running model inference. See the applicable service documentation for more details.”
AI supply chain10% of the scoreorganisation-level evidence40
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“This page provides information about the sub-processors that AWS has engaged in accordance with the AWS Data Processing Addendum (AWS DPA) to provide processing activities on Customer Data (as defined in the AWS DPA) on behalf of customers.”
Security foundation15% of the scoreorganisation-level evidence12
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
Vulnerability & incident handling: not publicly evidenced.
Independent assurance evidence10% of the scoreorganisation-level evidence55
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
Read from the registry record above — cited, not reproduced.
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the score60
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“50.3. You agree and instruct that for Amazon CodeGuru Profiler, Amazon Comprehend, Amazon Lex, Amazon Polly, Amazon Rekognition, Amazon Textract, Amazon Transcribe, Amazon Translate, AWS Transform, AWS FinOps Agent (Preview), Kiro Free Tier, and Kiro individual subscribers (as described here ): (a) we may use and store AI Content that is processed by each of the foregoing AI Services to develop and improve the applicable AI Service and its underlying technologies; (b) we may use and store AI Content that is not personal data to develop and improve AWS and affiliate machine-learning and artificial-intelligence technologies; and (c) solely in connection with the development and improvement described in clauses (a) and (b), we may store such AI Content in an AWS region outside of the AWS region where you are using such AI Service. This Section does not apply to Amazon Comprehend Medical, Amazon Transcribe Medical, AWS HealthScribe, Amazon Comprehend Detect PII or any AI Service that is not listed in the first sentence of this Section 50.3.”
“50.10.1. Subject to the limitations in this Section 50.10, AWS will defend you and your employees, officers, and directors against any third-party claim alleging that the Generative AI Output generated by an Indemnified Generative AI Service infringes or misappropriates that third party’s intellectual property rights, and will pay the amount of any adverse final judgment or settlement.”
““Indemnified Generative AI Services” means, collectively, generally available features of Amazon Nova Micro, Amazon Nova Lite, Amazon Nova Pro, Amazon Nova Premier, Amazon Nova Canvas, Amazon Nova Reel , Amazon Nova Forge Models (as defined below) , Amazon Nova Sonic, Amazon Nova 2 Omni, Amazon Nova Act, Amazon Titan Text Express, Amazon Titan Text Lite, Amazon Nova Multimodal Embeddings, Amazon Titan Text Premier, Amazon Titan Text Embeddings, Amazon Titan Multimodal Embeddings, Amazon Titan Image Generator, AWS HealthScribe, Amazon Personalize, Amazon Q (excluding Amazon Q Developer Free Tier), AWS Transform, Amazon Bio Discovery (excluding Amazon Bio Discovery Academic Tier), Amazon Connect Customer, Amazon Connect Decisions, Amazon Connect Health, Amazon Connect Talent, Amazon Lex, Kiro (excluding Kiro Free Tier), AWS DevOps Agent, AWS Security Agent, and Amazon Quick.”
Legal & contractual transparency: vendor-evidenced, not yet independently corroborated.
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 40 → up to 71 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 2 — registry checks and verification ladders, click to view
Not claimed in any public source scanned. This is the AI-management-system certification — in its absence, the vendor’s AI governance rests on its general security and privacy certifications.
Checked against FedRAMP Marketplace (fedramp.gov), Aug 31, 2026: Verified on the registry
Sources 13 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
