Is Amazon Web Services safe for
your vendor program?
- FedRAMP Status
- Amazon Web Services is listed on the FedRAMP Marketplace as Authorized (High) as of March 2026.
- SOC 2 Status
- Amazon Web Services has not had a SOC 2 claim detected on their trust page.
- Sanctions Screening
- Amazon Web Services returned no matches in OFAC SDN, EU Consolidated, and UN sanctions screening.
- Risk Tier
- ThirdProof assigned Amazon Web Services a Moderate Risk tier with 90% confidence across 24 intelligence sources.
ThirdProof investigated Amazon Web Services (aws.amazon.com) across 24 intelligence sources including sanctions databases, cyber risk scores, business registries, and more.
Verified against FedRAMP Marketplace API as of March 2026
Verified against the official FedRAMP Marketplace API as of March 2026.
AWS GovCloud authorized at High impact level. AWS commercial regions authorized at Moderate.
Investigation Preview — 23 Sources Queried
Full investigation report with evidence chain, compliance assessment, and recommended actions.
Investigate Amazon Web Services — First Investigation Free →Executive Summary Preview
Amazon Web Services (AWS) is assessed at Tier 3 (Moderate Risk), reflecting a small number of unresolved transparency and verification gaps rather than any indication of active threat, malicious activity, or regulatory enforcement. Across 21 independent data sources, AWS presents a strong technical security posture: its domain is 31 years established, all security engines return clean verdicts, infrastructure exposure is minimal with no known CVEs, and HTTP security headers earned a security header analysis grade of A (95/100).
This is an excerpt from the full ThirdProof investigation report. Get the complete report →
Key Findings for Amazon Web Services
| Severity | Finding | Source |
|---|---|---|
| info | Elevated community threat signals (infrastructure provider) | Threat Intelligence |
| low | No subprocessor page found | Supply Chain & Subprocessor Discovery |
| low | 5 certifications claimed but not independently verified | Trust & Compliance Page Scan |
4 total findings in the full report. View all findings →
Recommended Actions
- Obtain AWS's PCI DSS Attestation of Compliance (AoC) via AWS Artifact (https://aws.amazon.com/artifact) within 30 days. This document independently confirms PCI DSS compliance status and is required for your TPSP file under PCI-DSS 4.0 Requirement 12.8. Log in to your AWS account and navigate to AWS Artifact > Agreements & Reports to download it.
- Verify AWS FedRAMP authorization status independently by searching the FedRAMP Marketplace at https://marketplace.fedramp.gov for 'Amazon Web Services'. Note the specific authorization level (e.g., FedRAMP High) and document it alongside this report.
- Download the AWS SOC 2 Type II report via AWS Artifact (https://aws.amazon.com/artifact). This report provides independent third-party assurance over AWS's security, availability, and confidentiality controls. Retain with your vendor risk file.
Full recommendations available in the complete report.
“We manage nearly 100 vendors touching customer payment data. ThirdProof gives me audit-ready evidence in the time it used to take just to send the questionnaire.”
— April, Co-owner, The Perky Lady
What you'll see in Amazon Web Services's report
Every ThirdProof report includes these sections
Deterministic score based on evidence — not AI opinion
Understand how complete the picture is — higher confidence means more data sources returned results
Each finding linked to its source with severity rating
Know exactly what to do next — plain-language guidance for your compliance team
Independently verified, vendor attested, or not found
Audit-ready report with methodology disclosure
ThirdProof uses a deterministic rules engine to assign risk tiers. AI writes the narrative — rules drive the decision.
Intelligence Sources Queried for Amazon Web Services
Get Amazon Web Services's complete risk report — risk tier, confidence score, individual findings, and AI synthesis — in under 2 minutes.
Get Amazon Web Services's Risk Report Free →No credit card required
What a ThirdProof investigation covers
Sanctions Screening
Is Amazon Web Services on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
Cyber Risk Assessment
What is Amazon Web Services's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Business Registration
Is Amazon Web Services a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Adverse Media Analysis
Has Amazon Web Services appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Domain & Infrastructure
Is Amazon Web Services's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
Company Intelligence
What are Amazon Web Services's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Trust & Compliance Verification
Does Amazon Web Services claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Supply Chain & Subprocessor Discovery
Who does Amazon Web Services depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Regulatory & Financial Filings
Has Amazon Web Services appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Compliance Resources
Frequently asked about Amazon Web Services
Is Amazon Web Services safe to use as a vendor?+
Does Amazon Web Services have SOC 2 certification?+
Is Amazon Web Services FedRAMP authorized?+
Has Amazon Web Services had any data breaches?+
Is Amazon Web Services on any sanctions lists?+
How do I assess Amazon Web Services for vendor risk?+
Also investigated by ThirdProof
Get the full report on Amazon Web Services
Your first vendor investigation is completely free. Results in under 2 minutes.
Get Amazon Web Services's Risk Report Free →No credit card required
After your free investigation, plans start at $399/mo for up to 25 investigations.
Want a walkthrough of ThirdProof for your team?
▶Request a Personalized Demo