Skip to main content
Skip to main content

Amazon Web Services Vendor Risk & Security Assessment

ThirdProof independently checks public intelligence sources to show what your team can verify about Amazon Web Services before Amazon Web Services sends a questionnaire or a security document.

Amazon Web Services's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Amazon Web Services — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Amazon Web Services's own trust page.

FedRAMP Certified — Class D (High) Checked August 2026.

AWS GovCloud is FedRAMP Certified at Class D (High) via the JAB path (package F1603047866). AWS commercial regions are certified separately at Class C (Moderate).

Risk
Tier 5Minimal Risk
Evidence confidence
100%
26 of 27 sources returned data
Questionnaire
80 / 133 answered
60% from public evidence
Last assessed
Aug 27, 2026

Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.

🟢IP Reputation: Abuse score: 0%, 0 reports🟡SSL/TLS: TLSv1.3🟢Domain Age: 31.8 years🟢Infrastructure: 2 open ports, 0 CVEs
FedRAMP Status
Amazon Web Services is listed on the FedRAMP Marketplace — Independently verified (checked August 2026).
SOC 2 Status
Amazon Web Services — SOC 2: No public claim found. SOC 2 reports are confidential with no public registry, so compliance status is not publicly verifiable. Request the full Type II report and bridge letter directly from the vendor.
Sanctions Screening
Amazon Web Services returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
Risk Tier
ThirdProof assigned Amazon Web Services a Minimal Risk tier across 27 intelligence sources, 26 of which returned usable evidence (evidence confidence 100%).

27 sources queried, 26 returning usable evidence. The Amazon Web Services assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.

Get the Latest Amazon Web Services Vendor Assessment →
Full risk assessment + 133-question security questionnaire|Free · Delivered by email

Certification & Compliance Status

Security questionnaire — auto-filled

80 questions answered before Amazon Web Services responds.

ThirdProof used public evidence to pre-fill 60% of a 133-question vendor security questionnaire — without waiting for Amazon Web Services. The remaining 53 are listed as open, so the follow-up you send is short and specific.

Q39

Are you PCI DSS compliant? At what level?

PCI DSS compliance claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q42

Are you GDPR compliant? Do you have a DPA available?

GDPR compliance / DPA claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q40

Are you HIPAA compliant? Do you sign BAAs?

HIPAA compliance / BAA claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q38

Do you have ISO 27001 certification?

ISO 27001 claim found on trust page (Vendor attested)

Public evidencemedium confidence

Q41

Are you FedRAMP authorized? At what level?

FedRAMP authorized: Reconciled from trust page scan: AWS GovCloud found in FedRAMP Marketplace at https://marketplace.fedramp.gov/products/F1603047866

Public evidencehigh confidence

+ 75 additional evidence-backed answers

Get the Complete Amazon Web Services Assessment →

See all 133 questions, evidence links, findings, and the vendor follow-ups still required.

What you can verify before Amazon Web Services sends anything

Independent evidence settles part of the review. The rest still needs the vendor.

Public evidence establishes

  • FedRAMP — independently verified
  • FedRAMP Authorization Independently Verified
  • FedRAMP Authorization Confirmed (Cross-Source)
  • No SEC Enforcement Filings Found
  • Legal Entity Actively Registered
  • Vendor Commits to Not Training on Customer Data

Still requires vendor confirmation

  • Data Security — 9 of 14 questions need vendor input
  • Access Control — 7 of 12 questions need vendor input
  • Incident Response — 7 of 10 questions need vendor input
  • Governance & Risk — 4 of 10 questions need vendor input

Reviewing Amazon Web Services for your company?

Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.

5 vendors free · No credit card

Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing

Executive Summary

Narrative analysis for Amazon Web Services

Amazon Web Services (AWS) presents a minimal risk profile (Tier 5) with strong independent verification of critical security controls and certifications.

Area Requiring Attention

AWS demonstrates excellent security fundamentals, including FedRAMP Authorization at the High impact level, a designated Chief Information Security Officer (Chris Betz, appointed August 2023), formal risk assessment and monitoring programs, and an explicit commitment to not training AI models on customer data. The vendor maintains a clean domain reputation, modern TLS infrastructure (TLSv1.3), and a minimal attack surface (2 open ports: 80, 443 only).

The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.

Independence Statement

All evidence was independently sourced from external data sources, including public registries (FedRAMP Marketplace, certification databases), domain analysis, threat intelligence, and the vendor's published trust pages—without vendor participation in data collection.

Security Strengths

Evidence that positively supports Amazon Web Services's posture

Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.

FedRAMP Authorization Independently Verified

Trust & Compliance Page Scan

FedRAMP Authorization Confirmed (Cross-Source)

Certification Registry Verification

No SEC Enforcement Filings Found

SEC Filing Search

Legal Entity Actively Registered

Business Registration

Vendor Commits to Not Training on Customer Data

AI Data Usage Policy

Clean domain reputation

Threat Intelligence

Clean Safe Browsing Status

Malware & Phishing Check

Amazon Web Services complete vendor assessment

Tier 5
Minimal Risk
80 / 133
questionnaire answers
27
sources checked
Aug 27, 2026
assessment date
  • Complete 133-question security questionnaire
  • Evidence behind every answered item
  • Full findings and risk rationale
  • Recommended vendor follow-ups
  • Source and evidence inventory
  • Source-cited PDF assessment

Free · No account required

Latest ThirdProof assessment: Aug 27, 2026. Requesting it sends that existing report — it does not start a new investigation.

Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.

Frequently asked about Amazon Web Services

Does Amazon Web Services have SOC 2 Type II?+
Amazon Web Services was not found in the Vendor trust page when it was checked on August 27, 2026. Absence of a public record is not evidence that the certification is absent; organisations with a hard requirement should confirm directly with the vendor.
Is Amazon Web Services on the OFAC sanctions list?+
Amazon Web Services returned no matches in ThirdProof's OFAC SDN, EU Consolidated, and UN sanctions screening as of August 2026.
What is Amazon Web Services's vendor risk tier?+
ThirdProof assigned Amazon Web Services a risk tier of Minimal Risk as of August 2026, with an evidence confidence of 100% across 27 intelligence sources. Evidence confidence describes how much of the evidence ThirdProof set out to gather it was able to gather — not certainty about every fact concerning Amazon Web Services.
Has Amazon Web Services had any data breaches or security incidents?+
ThirdProof's adverse media and incident screening as of August 2026 did not surface a validated security incident involving Amazon Web Services. Public sources do not record every incident, so this is not a guarantee that none occurred — ask Amazon Web Services directly for its incident disclosure history and breach notification commitments.
Is Amazon Web Services PCI DSS compliant?+
PCI DSS compliance claim found on trust page (Vendor attested) ThirdProof records this from Amazon Web Services's published compliance evidence; request the current Attestation of Compliance to confirm the scope that applies to your integration.
Does Amazon Web Services support HIPAA and sign BAAs?+
HIPAA compliance / BAA claim found on trust page (Vendor attested) If protected health information is in scope for your use, confirm BAA availability in writing before contracting.
Can ThirdProof pre-fill a Amazon Web Services security questionnaire?+
Yes. ThirdProof answered 80 of 133 questions (60%) about Amazon Web Services from public evidence, before contacting the vendor. Each answered item carries the evidence it was drawn from. The remaining 53 are listed as open, so the follow-up you send Amazon Web Services is short and specific.
What evidence should I request from Amazon Web Services?+
Public evidence settles a large part of the review, so the request you send should be short. Ask Amazon Web Services for the audit scope — which systems and services the report actually covers; written answers on data security, access control, incident response; contractual commitments, cyber insurance, and the current subprocessor list. Everything ThirdProof could already establish is recorded with its source, so you are not asking Amazon Web Services to re-confirm what is already documented.

Represent Amazon Web Services? Submit updated security evidence.

If Amazon Web Services is in your vendor stack, can you prove you assessed them?

SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Amazon Web Services assessment above is already written; ask for it and it lands in your inbox.

✓ This assessment: free, no account required✓ Your first 5 vendor investigations are free✓ No credit card required