Amazon (AWS) AI Vendor Risk Profile

Cloud infrastructure leader that develops proprietary Titan models and custom Trainium/Inferentia chips while offering multi-model access through Amazon Bedrock, hosting Anthropic, Meta, Mistral, and others. Strategic investor in Anthropic.

Visit Amazon (AWS) website

HQ: United States · Hybrid

Risk overview

Risk score: 12/100

Risk tier: Low

Safety rating: 88/100 (higher is better)

Lower risk scores indicate lower assessed risk.

Last verified: Apr 19, 2026 (107 days ago) Aging · 8 cited sources

Risk dimensions

DimensionRisk score
Data Handling14/100
IP Exposure6/100
Jurisdiction13/100
Security18/100
Regulatory Compliance10/100
Transparency15/100
Business Stability9/100
Dependency Chain17/100
Agent GovernanceNot assessed

Analyst summary

Rating: Recommended

Amazon Bedrock provides enterprise-grade access to multiple foundation models (Claude, Llama, Titan, Mistral, Cohere, and others) within AWS's compliance perimeter. It inherits the full AWS compliance stack and offers uncapped IP indemnification on select models. Complexity is the cost.

Bottom line: The default enterprise AI layer for AWS-standardized organizations; over-complex if you are not already on AWS.

Strengths

Concerns

Best for

Avoid if

Citations

  1. Data Handling — Data Retention Period (primary · high confidence)
    https://docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html
    Verified 2026-04-19
    Amazon Bedrock does not store your prompts or completions after the request is processed unless you enable model invocation logging.
  2. Data Handling — Hipaa Baa Available (primary · high confidence)
    https://aws.amazon.com/compliance/hipaa-compliance/
    Verified 2026-04-19
    AWS offers a Business Associate Addendum (BAA) covering Amazon Bedrock, SageMaker, and other HIPAA-eligible services.
  3. Data Handling — Trains On User Data (primary · high confidence)
    https://aws.amazon.com/machine-learning/bedrock/faqs/
    Verified 2026-04-19
    Amazon Bedrock does not use your inputs or outputs to train any AWS or third-party models. Your data is not shared with model providers.
  4. Ip Profiles — Indemnification Offered (primary · high confidence)
    https://aws.amazon.com/machine-learning/generative-ai-ip-indemnification/
    Verified 2026-04-19
    AWS offers uncapped IP indemnity for generally available Amazon Titan models and certain third-party models on Bedrock.
  5. Jurisdiction Profiles — Incorporation Country (official · high confidence)
    https://www.aboutamazon.com/news/company-news
    Verified 2026-04-19
    Amazon.com, Inc. is a Delaware corporation headquartered in Seattle, Washington (SEC Form 10-K).
  6. Security Compliance — Fedramp Authorized (primary · high confidence)
    https://aws.amazon.com/compliance/fedramp/
    Verified 2026-04-19
    AWS GovCloud holds FedRAMP High authorization, and AWS US East/West holds FedRAMP Moderate, covering Bedrock for authorized regions.
  7. Security Compliance — Iso 27001 (primary · high confidence)
    https://aws.amazon.com/compliance/iso-27001-faqs/
    Verified 2026-04-19
    AWS is certified to ISO/IEC 27001 with scope including all generally available AI/ML services.
  8. Security Compliance — Soc2 Type2 (primary · high confidence)
    https://aws.amazon.com/compliance/soc-faqs/
    Verified 2026-04-19
    AWS services including Bedrock are covered by SOC 2 Type II reports available via AWS Artifact.