AI Provider Trust Registry evidence verified as of 2026-10-03

Registry / Claude via AWS Bedrock

Claude via AWS Bedrock

developer: Anthropic platform: AWS Bedrock category: cloud distribution

Anthropic's Claude models served through Amazon Bedrock, AWS's managed foundation-model service. Vendor-trust and data-handling posture is AWS's (SOC/ISO scope, AWS BAA, GDPR DPA, Bedrock retention controls); EU AI Act provider obligations (GPAI Code of Practice, Art 53) sit with Anthropic as the model developer.

Watch-outs 4

The cells where this offering is not a clean public yes. This is what to check before you sign.

Vendor trust
SOC 2 Type II Is a SOC 2 Type II report available for this offering?
◐Yes, sales-gated confidence: high · verified 2026-09-27

Audit confirmed: trust.anthropic.com is Anthropic's own Trust Center showing SOC 2 Type 2 in scope with the "Type 2 SOC 2 and CSA STAR L2 Report.pdf" resource, but sensitive documents (including the report) require a request-access form, so the recorded value stands as yes_sales_gated.

To access sensitive documents, please click the "request access" button at the top of the page and complete the request form.

source

ISO 27001 Is there an ISO/IEC 27001 certification covering this offering?
●Yes, public confidence: high · verified 2026-10-03

Anthropic’s Trust Center publicly lists ISO 27001 certification as covering the model itself, which includes Claude when offered via AWS Bedrock.

ISO 27001 ... ✅ ... (Only applicable to the model themselves and containers supplied to partners by Anthropic)

source

ISO 42001 Is there an ISO/IEC 42001 (AI management system) certification?
●Yes, public confidence: high · verified 2026-10-01

Anthropic, the developer of Claude, publicly confirms ISO/IEC 42001 certification for its AI management system, which by policy covers Claude on all platforms including AWS Bedrock.

We are excited to announce that Anthropic has achieved accredited certification under the new ISO/IEC 42001:2023 standard for our AI management system.

source

Trust center Is there a maintained trust center / compliance portal?
●Yes, public confidence: high · verified 2026-10-01

AWS Artifact is a publicly documented, self‑service compliance portal that all AWS accounts can access, confirming a maintained trust center.

All AWS Accounts have access to AWS Artifact. Root users and IAM users with admin permissions can download all audit artifacts available to their account.

source

Data handling
HIPAA BAA Will they sign a HIPAA Business Associate Agreement covering this offering?
◐Yes, sales-gated confidence: high · verified 2026-10-02

AWS lists Amazon Bedrock as HIPAA‑eligible but requires customers to first sign an AWS Business Associate Agreement, which is only available through the gated AWS Artifact portal.

NOTE: If you are a Covered Entity or Business Associate ... you agree not to use these HIPAA Eligible Services ... without first entering into an AWS business associate agreement.

source

GDPR DPA Is there a public DPA with SCCs and a published subprocessor list?
●Yes, public confidence: high · verified 2026-09-30

AWS provides a publicly accessible GDPR Data Processing Addendum that includes SCC language and references a publicly listed sub‑processor page, covering all AWS services including Bedrock.

Taking into account the nature of the processing, Customer agrees that it is unlikely that AWS would become aware that Customer Data transferred under the Standard Contractual Clauses is inaccurate or outdated... 6.1 Authorized Sub‑processors. ... The AWS website (currently posted at https://aws.amazon.com/compliance/sub‑processors/) lists Sub‑processors that are currently engaged by AWS.

source

No-training default Is there a public commitment not to train on customer API data by default?
●Yes, public confidence: high · verified 2026-09-30

The AWS Bedrock FAQ publicly commits that customer content is not used to improve base models, confirming a default no‑training‑on‑API‑data policy for Claude via Bedrock.

With Amazon Bedrock, your content is not used to improve the base models and is not shared with any model providers.

source

Retention / ZDR Is retention documented, and is zero-data-retention available?
◔Partial confidence: high · verified 2026-10-03

AWS docs confirm retention settings are publicly documented and state that ZDR applies only to pre‑Fable 5 Claude models, so the claim is only partially satisfied.

Important: There is no data retention change to Claude models released before Claude Fable 5. ... `none` Zero data retention. No request or response data is written to durable storage by AWS or shared with the model provider.

source

Residency Can data be pinned to a region (especially the EU)?
●Yes, public confidence: high · verified 2026-09-29

AWS Bedrock model card for Claude Sonnet 5 publicly lists an EU inference profile that pins data to EU regions.

EU geo(`eu.anthropic.claude-sonnet-5`): Keeps data within EU regions.

source

EU AI Act
GPAI Code Is the model developer on the EC's GPAI Code of Practice signatory list?
●Yes, public confidence: high · verified 2026-09-28

Anthropic is listed among the signatories on the EU Commission's official GPAI Code of Practice signatory page, confirming the model developer is a signatory.

- Anthropic

source

Art. 53 summary Has the model developer published the Art. 53 training-data summary?
◐Yes, sales-gated confidence: high · verified 2026-09-28

Anthropic’s Trust Center page for the Claude Sonnet 5 training‑data summary is gated behind a request‑access form, confirming the summary is not publicly available.

To access sensitive documents, please click the "request access" button at the top of the page and complete the request form.

source

Spotted an error? Submit a correction with evidence, corrections with a primary source are folded in and credited in the changelog.