Skip to main content
TrustEdge AI
Deployment platform

Amazon Bedrock

Deployment platform. Hosts third-party foundation models inside the customer’s AWS account and region under AWS commercial terms — frequently the compliant route to a model whose direct API is not.

6 of 7 criteria carry a sourced value · 1 recorded as a gap ·  Verified August 8, 2026

What this means for a regulated buyer

Our analysis, not Amazon Bedrock’s. Every statement here traces to a sourced claim further down the page.

The widest certification coverage in the table, an enforceable zero-retention mode, and one carve-out that a blanket reading of the marketing would miss entirely.

Where it is strong

  • Retention is the only one here that is machine-enforceable: mode "none" can be mandated organisation-wide by Service Control Policy rather than requested from a support desk.
  • Certification breadth spans SOC 1/2/3, seven ISO standards, FedRAMP Moderate and CSA STAR Level 2.
  • Model providers have no access to the deployment accounts, and therefore none to logs, prompts or completions.
  • Sub-processor changes carry a contractual 30 days’ advance notice.
  • Hosts models from three developers tracked here — Anthropic, Meta and Mistral — under one set of platform terms.

What to check or negotiate

  • Two AWS pages are in tension. The FAQ states content "is not shared with any model providers"; the retention documentation carves out Claude Fable 5 and Claude Mythos 5, which require provider data sharing and are shared with Anthropic for up to 30 days.
  • Those same two models are excluded from HIPAA eligibility, recorded as "Amazon Bedrock [excluding Fable and Mythos models]". Eligibility here is per-model, not per-service.
  • AWS warns that setting store=false "does not guarantee zero data retention" — only data_retention_mode: none does.
  • ZDR on models that require retention is granted per-account and per-model, in coordination with the model provider.
  • No ISO/IEC 42001 — the AI management system standard that both Anthropic and OpenAI list.

Verdict

The strongest platform posture here for a buyer who can enforce retention policy centrally — provided the model selection is checked against the HIPAA exclusion list rather than the service name.

The full record

Every criterion, with Amazon Bedrock’s own wording where it is hedged or carries exclusions, the primary source, and the date we last read it.

FLI safety grade

Safety-research posture, per the Future of Life Institute

Not applicable

FLI grades model developers, not deployment platforms. The safety grades that bear on this row belong to the developers whose models it hosts — Anthropic, Meta and Mistral are all tracked here separately, and their grades span C+ to F. The compliance terms below are Amazon’s and apply regardless of which of those models is selected.

Primary source · verified 2026-08-07

BAA available

Will they sign a business associate agreement for PHI

Yes

Listed among AWS HIPAA Eligible Services, but with a model-level carve-out recorded verbatim as "Amazon Bedrock [excluding Fable and Mythos models]"; Amazon Bedrock AgentCore is listed separately. AWS states that covered entities "agree not to use these HIPAA Eligible Services for any purpose or in any manner involving Protected Health Information… without first entering into an AWS business associate agreement." Eligibility is per-service and here per-model — check the specific model, not the service.

Primary source · verified 2026-08-07

Certifications

Independently audited attestations

SOC 1, SOC 2, SOC 3 · ISO 9001 · ISO/IEC 27001 · ISO/IEC 27017 · ISO/IEC 27018 · ISO/IEC 27701 · ISO 22301 · ISO/IEC 20000 · FedRAMP Moderate · CSA STAR Level 2 · HIPAA eligible

AWS: "Amazon Bedrock is one of the AWS services under ISO Compliance for the ISO 9001, ISO 27001, ISO 27017, ISO 27018, ISO 27701, ISO 22301, and ISO 20000 standards", and it "is included in the scope of the SOC 1, 2, 3 reports". The breadth is the widest of any row here, though note the absence of ISO/IEC 42001, the AI management system standard that Anthropic and OpenAI both list.

Primary source · verified 2026-08-07

Trains on your data

Whether your inputs and outputs feed model training

Not by default — No training use of customer content, and no sharing with model providers — except for models that require provider data sharing as a condition of access, which must be enabled deliberately.

Two AWS pages sit in tension and the narrower one governs. The FAQ states flatly that "your content is not used to improve the base models and is not shared with any model providers" and that AWS and third-party providers "will not use any inputs to or outputs from Amazon Bedrock to train Amazon Nova, Amazon Titan, or any third-party models." The data retention documentation then carves out an exception: "Claude Fable 5 and Claude Mythos 5 require provider data sharing (allowed_modes: ['provider_data_share']). Customers must explicitly set their data retention mode to provider_data_share before they can invoke these models." Sharing is opt-in and the models are simply unavailable otherwise, so the default holds — but the blanket FAQ sentence is no longer true of every model on the platform. These are the same two models excluded from HIPAA eligibility above.

Primary source · verified 2026-08-07

Retention

How long your data is kept, and where

Customer-controlled through four retention modes set at account or project scope, including an enforceable zero-retention mode.

Modes are default, provider_data_share, none and inherit, resolved project → account → model default. Mode none is "Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider", and it can be enforced organisation-wide by Service Control Policy — the only vendor here where retention posture is machine-enforceable rather than a support request. Two caveats: for models requiring provider_data_share, "user prompts and completions are shared with Anthropic and retained for up to 30 days for trust and safety purposes"; and AWS warns that "Setting store=false does not guarantee zero data retention." ZDR on retention-requiring models is "evaluated on a per-account, per-model basis in coordination with the model provider."

Primary source · verified 2026-08-07

Subprocessors

Who else processes your data

Named list by category and region with a contractual 30 days’ advance notice before any new sub-processor is engaged, plus email notification on subscription.

AWS: "AWS will update this page at least 30 days before engaging a new sub-processor, and if you subscribe for updates, AWS will notify you by email of changes to this page." Last updated July 28, 2026. Sub-processors are split into four types, with those for the AWS European Sovereign Cloud listed separately. Shorter notice than Microsoft’s six months, but unlike OpenAI and Mistral it is a committed period rather than best-effort notification.

Primary source · verified 2026-08-07

EU AI Act

Obligations, and which transfer to you as deployer

Amazon is a signatory to the EU General-Purpose AI Code of Practice, the voluntary route to demonstrating compliance with the AI Act.

The signatory is Amazon, the platform operator, and the commitment does not travel to the third-party models hosted on the platform. Anthropic and Mistral are signatories in their own right; Meta, whose models are also hosted here, is not listed.

Primary source · verified 2026-08-07

This is a deployment platform, so it carries no FLI safety grade — FLI grades model developers. The safety grade that bears on your deployment belongs to whichever model you run here; the compliance terms above are the platform’s and apply regardless of that choice.

Hosts models from Anthropic, Meta and Mistral AI. Running one of those models here means the safety grade is theirs and the terms above are this platform’s.

Safety grades come from the FLI AI Safety Index, Summer 2026 — what it measures, and what it explicitly does not.

Deploying Amazon Bedrock in a regulated environment

We help regulated organisations build AI vendor diligence that holds up in an audit.