Q39
Are you PCI DSS compliant? At what level?
PCI DSS compliance claim found on trust page (Vendor attested)
ThirdProof independently checks public intelligence sources to show what your team can verify about Amazon Web Services before Amazon Web Services sends a questionnaire or a security document.
Amazon Web Services's SOC 2 report is confidential. There is no public registry for SOC 2, so the report itself has to come from Amazon Web Services — ThirdProof does not hold or distribute it. What this page gives you is an independent assessment built from evidence anyone can check, and a record of which certifications are registry-verified versus claimed on Amazon Web Services's own trust page.
✓ FedRAMP Certified — Class D (High) Checked August 2026.
AWS GovCloud is FedRAMP Certified at Class D (High) via the JAB path (package F1603047866). AWS commercial regions are certified separately at Class C (Moderate).
Evidence confidence measures how much of the evidence ThirdProof set out to gather it was able to gather and corroborate. It is not a statement that every fact about this vendor is known.
27 sources queried, 26 returning usable evidence. The Amazon Web Services assessment ThirdProof has already run covers both a risk report and an auto-filled security questionnaire, with anything the evidence could not settle listed as an open question.
Get the Latest Amazon Web Services Vendor Assessment →Security questionnaire — auto-filled
ThirdProof used public evidence to pre-fill 60% of a 133-question vendor security questionnaire — without waiting for Amazon Web Services. The remaining 53 are listed as open, so the follow-up you send is short and specific.
Q39
PCI DSS compliance claim found on trust page (Vendor attested)
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
FedRAMP authorized: Reconciled from trust page scan: AWS GovCloud found in FedRAMP Marketplace at https://marketplace.fedramp.gov/products/F1603047866
+ 75 additional evidence-backed answers
See all 133 questions, evidence links, findings, and the vendor follow-ups still required.
Independent evidence settles part of the review. The rest still needs the vendor.
Reviewing Amazon Web Services for your company?
Get the complete ThirdProof assessment now, then use the same workflow to assess the rest of your vendor stack.
5 vendors free · No credit card
Need ongoing vendor reviews? ThirdProof includes up to 50 vendor assessments per month for $399. See pricing
Narrative analysis for Amazon Web Services
Amazon Web Services (AWS) presents a minimal risk profile (Tier 5) with strong independent verification of critical security controls and certifications.
AWS demonstrates excellent security fundamentals, including FedRAMP Authorization at the High impact level, a designated Chief Information Security Officer (Chris Betz, appointed August 2023), formal risk assessment and monitoring programs, and an explicit commitment to not training AI models on customer data. The vendor maintains a clean domain reputation, modern TLS infrastructure (TLSv1.3), and a minimal attack surface (2 open ports: 80, 443 only).
The full risk rationale, every finding and the recommended vendor follow-ups are in the complete assessment below.
Independence Statement
All evidence was independently sourced from external data sources, including public registries (FedRAMP Marketplace, certification databases), domain analysis, threat intelligence, and the vendor's published trust pages—without vendor participation in data collection.
Evidence that positively supports Amazon Web Services's posture
Neutral observations, source coverage notes and items ThirdProof could not independently establish are recorded separately in the complete assessment — they are not counted as strengths.
FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →FedRAMP Authorization Confirmed (Cross-Source)
Certification Registry Verification →No SEC Enforcement Filings Found
SEC Filing Search →Legal Entity Actively Registered
Business Registration →Vendor Commits to Not Training on Customer Data
AI Data Usage Policy →Clean domain reputation
Threat Intelligence →Clean Safe Browsing Status
Malware & Phishing Check →Amazon Web Services complete vendor assessment
Risk tiers are set by a deterministic rules engine. AI summarises sourced evidence and writes the narrative; it does not assign the tier. Read the full methodology.
Represent Amazon Web Services? Submit updated security evidence.
SOC 2 CC9.2, HIPAA, PCI DSS and CMMC all require documented vendor due diligence — not just knowing the answer, but holding evidence that you verified it. The Amazon Web Services assessment above is already written; ask for it and it lands in your inbox.