Skip to main content

Amazon Bedrock

Amazon Bedrock uses a zero operator access and zero data retention model, so by default it does not store model inputs or outputs. Some models require retention for abuse detection, capped at 30 days within the AWS boundary and never shared with the model provider. Retention is set by mode at account or project level and can be locked by policy.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AVD-2026-0026
Kind
API and platform
Jurisdiction
United States
Last verified
Added
  • Amazon Bedrock uses a zero data retention security model, so by default it does not store model inputs or outputs.
  • Where a model requires retention, prompts and completions are held within the AWS boundary for up to 30 days and are not shared with the model provider.
  • Model providers have no access to the deployment accounts, so they see neither logs nor customer prompts and completions.
  • Retention is a mode set at account or project level, and an organisation can require the zero retention mode through a service control policy.

Dimension by dimension

10 dimensions, each one stated, silent or open

Used for training by default, Retention period, Deletion on request, Storage region and residency, Subprocessor list published, Human review of content, Opt out available, DPA available, Persistent memory across sessions, Last change to the terms. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

Used for training by defaultStated
Providers are structurally excluded. They have no access to the deployment accounts and therefore none to Bedrock logs or to customer prompts and completions.AWS documentation, Amazon Bedrock data protection, primary source, 15 September 2026.
Retention periodStated
Zero by default, with named models requiring up to 30 days for abuse detection, and per feature behaviour where the customer chooses to store responses.AWS documentation, Amazon Bedrock data retention, primary source, 15 September 2026.
Deletion on requestSilent
Expressed as an automatic cap rather than a deletion right. No customer initiated deletion of retained abuse data is described.AWS documentation, Amazon Bedrock data retention, primary source, 15 September 2026.
Storage region and residencyStated
Retained inputs and outputs are stored in the destination region where the request is processed, and a model deployment account exists per provider per region.AWS documentation, Amazon Bedrock abuse detection, primary source, 15 September 2026.
Subprocessor list publishedStated
The model providers are the third parties and they are walled off. Bedrock does not share customer content with model providers today.AWS documentation, Amazon Bedrock data retention, primary source, 15 September 2026.
Human review of contentStated
Only where a provider requires it as a condition of access, performed by AWS inside the AWS boundary, and the content does not leave AWS.AWS documentation, Amazon Bedrock data retention, primary source, 15 September 2026.
Opt out availableStated
Zero retention is set by API and can be enforced across an organisation by policy, and for models that require retention it is evaluated per account and per model.AWS documentation, Amazon Bedrock data retention, primary source, 15 September 2026.
DPA availableSilent
The Bedrock data protection pages point to the service terms and a regulatory centre rather than naming a data processing addendum.AWS documentation, Amazon Bedrock data protection, primary source, 15 September 2026.
Persistent memory across sessionsStated
Persistence is a request level choice through the responses API, and the documentation warns that setting store to false does not guarantee zero retention.AWS documentation, Amazon Bedrock data retention, primary source, 15 September 2026.
Last change to the termsStated
The Bedrock user guide pages print no date. The AWS service terms print Last Updated 15 September 2026.AWS service terms, primary source, 15 September 2026.

Figures

Every number, with who measured it and when

  1. 30 days

    Retention cap for models that require review

    AWS documentation, Amazon Bedrock data retention, primary source, as of .

  2. 30 days

    Abuse detection retention for flagged traffic

    AWS documentation, Amazon Bedrock abuse detection, primary source, as of .

What it changes

For a buyer or a workplace AI policy

Retention here is a property of the model you call, not of the platform you bought. A single account can be zero retention for one model and thirty days with human review for another, because each model declares the modes it allows, and the more permissive setting is what unlocks certain models at all. Any statement you make to a customer about retention has to name the models in the deployment, not the service.

Sources

What this record was verified against

  1. AWS documentation, Amazon Bedrock data protectionPrimary · 15 September 2026
  2. AWS documentation, Amazon Bedrock data retentionPrimary · 15 September 2026
  3. AWS documentation, Amazon Bedrock abuse detectionPrimary · 15 September 2026
  4. AWS service termsPrimary · 15 September 2026

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AVD-2026-0026 is permanent and is never reused.

In a sentence
According to the GAGE AI Vendor Data Ledger (as of 15 September 2026), amazon bedrock.
APA
GAGE (Global Academy of Generative-AI Education). (2026). Amazon Bedrock. AI Vendor Data Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0026-amazon-bedrock
MLA
"Amazon Bedrock." AI Vendor Data Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0026-amazon-bedrock.
Chicago
GAGE (Global Academy of Generative-AI Education). "Amazon Bedrock." AI Vendor Data Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0026-amazon-bedrock.
Permalink
https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0026-amazon-bedrock

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any terms change a vendor announces.

Back to the full ledger, or every record for United States and every api and platform record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.