Amazon Bedrock — privacy & data policy
Provider: AWS. PromptPrivacy score: 83/100. Last verified August 26, 2026.
What happens to your data?
Your data remains under your ownership and control, encrypted both in transit and at rest. It is not shared with external model providers or used to train base foundation models. Customizations take place on private copies of models within your secure AWS environment.
Does it train on your data?
Customer data is not shared with model providers and is not used to improve or train base models. Fine-tuning models is performed on a private copy of the foundation model.
Can you opt out?
Not specified, as customer data is excluded from base model training by default.
Data retention
Not specified in the provided text. However, customers can choose to store metadata, requests, and responses in their own Amazon S3 buckets and Amazon CloudWatch Logs.
Encryption & security
Data is encrypted both in transit and at rest. Users can create and manage their own encryption keys via AWS Key Management Service (AWS KMS). The service supports AWS PrivateLink and complies with ISO, SOC, CSA STAR Level 2, HIPAA, GDPR, and FedRAMP High standards.
Is it safe for work?
Yes. Amazon Bedrock offers robust enterprise security controls including KMS key management, IAM identity policies, VPC PrivateLink, automated abuse detection, and major compliance accreditations (SOC, ISO, HIPAA, GDPR, and FedRAMP High).
Source policy: https://aws.amazon.com/bedrock/security-compliance/