Q37
Do you have a current SOC 2 Type II report?
SOC 2 Type II: claimed_with_trust_page
Before you share customer data with Amazon Web Services, your compliance team needs documented proof they can be trusted. ThirdProof investigated Amazon Web Services across 27 intelligence sources — here's what we found.
✓ FedRAMP Status: Authorized (High) — verified against marketplace.fedramp.gov
27 sources queried. 100% confidence. Every Amazon Web Services investigation produces both a risk report and an auto-filled security questionnaire — no vendor follow-up required.
Get Amazon Web Services's Full Report Free →Security Questionnaire — Auto-Filled
Auto-filled from public evidence • 47% complete
Q37
SOC 2 Type II: claimed_with_trust_page
Q38
ISO 27001 claim found on trust page (Vendor attested)
Q41
FedRAMP authorized: Reconciled from trust page scan: AWS GovCloud found in FedRAMP Marketplace at https://marketplace.fedramp.gov/products/F1603047866
Q40
HIPAA compliance / BAA claim found on trust page (Vendor attested)
Q42
GDPR compliance / DPA claim found on trust page (Vendor attested)
+ 6 more compliance questions answered in the full report
Every investigation produces a full PDF report plus the complete 133-question questionnaire, mapped to SOC 2, HIPAA, PCI DSS, SIG, and more.
Get Amazon Web Services's Full Report Free →Verified against FedRAMP Marketplace API as of March 2026
Verified against the official FedRAMP Marketplace API as of March 2026.
AWS GovCloud authorized at High impact level. AWS commercial regions authorized at Moderate.
Minimal Risk
Vendor Risk Assessment
Based on data availability and source coverage
27
Sources Queried
27
Sources With Data
April 17, 2026
Last Assessed
AI-generated analysis for AWS
Amazon Web Services (AWS), the cloud infrastructure division of Amazon.com, Inc., presents a Tier 5 (Minimal Risk) profile — the highest rating available on the ThirdProof scale — supported by a 100% confidence score across 24 independent data sources. AWS demonstrates an exceptionally strong security and compliance posture across all assessed dimensions.
The sole area requiring attention is a cross-source contradiction (CONTRA-1): while AWS's compliance programs page lists ISO 27001, HITRUST CSF, and PCI DSS among its certifications, independent registry lookups (IAF CertSearch, HITRUST directory, and PCI SSC) did not return confirming results during this assessment. This does not indicate non-compliance — AWS's scale and certification structure (covering hundreds of services and regions) makes registry matching inherently difficult — but procurement teams should request current certificate copies directly from AWS for audit chain completeness. SOC 2 Type II is claimed on the vendor's trust page; as with all SOC 2 reports, no public registry exists and the full report should be obtained directly. Overall, AWS represents one of the most comprehensively assessed and externally validated cloud infrastructure providers available. The Tier 5 rating reflects a mature, well-documented security program with no active risk signals across any assessed dimension.
Independence Statement
All evidence in this assessment was sourced independently from public registries, threat intelligence feeds, DNS/TLS analysis, and external media archives without vendor participation or input.
4 findings identified for AWS
3 Hacker News stories about "Amazon Web Services" related to operational. Top story: "Systems Correctness Practices at Amazon Web Services" (383 points).
aws.amazon.com has certificates from 7 different Certificate Authorities. This may indicate inconsistent certificate management practices.
aws.amazon.com first appeared less than 1 year ago (2026-02-05). This indicates a relatively new web presence.
aws.amazon.com has no MX records, meaning it cannot receive email directly.
37 positive signals verified
No Threat Intelligence Pulses
Threat Intelligence (OTX) →Legal Entity Actively Registered
Business Registration →Sanctions Data Incomplete
Sanctions & Watchlist Screening →Low-Confidence Sanctions Matches Only
Sanctions & Watchlist Screening →No Adverse Media Found
Adverse Media Scan →No Adverse Media Signals
Adverse Media Scan (Fallback) →Firmographic Data Available
Company Intelligence →Valid SSL Certificate
Domain Analysis →2 Open Ports Detected
Infrastructure Exposure →Established Domain (31+ years)
Domain Registration →Clean domain reputation
Threat Intelligence →HTTP Security Grade: A
HTTP Security Scan →Large Certificate Footprint (752 subdomains)
Certificate Transparency →Clean IP Reputation
IP Reputation →Clean Safe Browsing Status
Malware & Phishing Check →Clean Website Security Scan
Website Security Scan →FedRAMP Authorization Independently Verified
Trust & Compliance Page Scan →Certification Claimed: PCI DSS
Trust & Compliance Page Scan →Certification Claimed: HIPAA
Trust & Compliance Page Scan →Certification Claimed: GDPR
Trust & Compliance Page Scan →Certification Claimed: NIST
Trust & Compliance Page Scan →Certification Claimed: SOC 2
Trust & Compliance Page Scan →Certification Claimed: SOC 1
Trust & Compliance Page Scan →Certification Claimed: ISO 27001
Trust & Compliance Page Scan →Certification Claimed: ISO 27017
Trust & Compliance Page Scan →Certification Claimed: ISO 27018
Trust & Compliance Page Scan →Certification Claimed: HITRUST
Trust & Compliance Page Scan →Certification Claimed: CSA STAR
Trust & Compliance Page Scan →Certification Claimed: Cyber Essentials
Trust & Compliance Page Scan →1 Subprocessors Identified
Supply Chain & Subprocessor Discovery →Not Found as FDIC-Insured Institution
FDIC Institution Check →No SEC Enforcement Filings Found
SEC Filing Search →No Historical Adverse Media Found
Historical Media Search →SOC 2 Compliance Claimed on Trust Page
Certification Registry Verification →FedRAMP Authorization Confirmed (Cross-Source)
Certification Registry Verification →Vendor Commits to Not Training on Customer Data
AI Data Usage Policy →Deep Document Crawler Results
Deep Document Analysis →Steps to address findings for AWS
Obtain AWS compliance reports via the [AWS Artifact portal](https://aws.amazon.com/artifact/) — this self-service portal provides on-demand access to SOC 1 Type II, SOC 2 Type II, ISO 27001 certificates, PCI DSS Attestations of Compliance, and FedRAMP documentation. Download the most recent SOC 2 Type II report and ISO 27001 certificate and retain them with this assessment report for your audit file.
Document your Complementary User Entity Controls (CUECs) if AWS is within your SOC 2 audit boundary. AWS's SOC 2 report specifies controls that AWS implements and controls that customers are expected to implement (e.g., IAM least privilege, MFA enforcement, CloudTrail logging). Request the AWS SOC 2 report from Artifact, review Appendix A (CUECs), and map each control to your internal implementation evidence.
Activate the Amazon Organizations AI services opt-out policy if your data handling policies require it. Log into your AWS Organizations management account, navigate to Policies > AI services opt-out policies, and apply the opt-out to your organization or specific accounts. Document the activation date and retain as a data governance record.
Review the full AWS subprocessor list directly at [aws.amazon.com/compliance/sub-processors/](https://aws.amazon.com/compliance/sub-processors/) to confirm completeness for your GDPR Article 28 vendor management obligations. The automated scan identified one entry; the live page may contain additional entries.
Confirm AI data retention duration with your AWS account team or via AWS Support. The [AI opt-out policy documentation](https://docs.amazonaws.cn/en_us/organizations/latest/userguide/orgs_manage_policies_ai-opt-out.html) does not specify a retention period for AI-processed data; this detail is material for data minimization compliance under GDPR and CCPA.
27 sources in this assessment
Some data sources may have had limited availability during this assessment. This does not reflect negatively on the vendor.
Are you Amazon Web Services? Claim this profile to complete your security record. Buyers are reviewing this profile now.
Claim this profile →Is Amazon Web Services on any OFAC, EU, or UN sanctions list? Are any officers or affiliates flagged?
What is Amazon Web Services's security posture? Threat intelligence scanning, known vulnerabilities, and security header analysis.
Is Amazon Web Services a legitimately registered business entity? Corporate status, jurisdiction, and officer verification.
Has Amazon Web Services appeared in negative news coverage? Data breaches, lawsuits, regulatory actions, and complaints.
Is Amazon Web Services's website secure? TLS configuration, DNS hygiene, security headers, and domain age analysis.
What are Amazon Web Services's firmographics? Employee count, industry classification, technology stack, and corporate structure.
Does Amazon Web Services claim SOC 2, ISO 27001, HITRUST, or FedRAMP? ThirdProof scans trust pages for certification claims and cross-references the FedRAMP public registry for independent verification.
Who does Amazon Web Services depend on? ThirdProof discovers subprocessors from vendor-published pages and runs sanctions screening and safe browsing checks against each one.
Has Amazon Web Services appeared in SEC enforcement filings? Is it associated with any FDIC bank failures? ThirdProof searches regulatory databases with entity verification to confirm attribution.
Full methodology, rule engine, and AI disclosure: /methodology
Seeing this in an audit? ThirdProof lets you investigate Amazon Web Services and every other vendor in your stack — average report time: 7 minutes. Get Amazon Web Services's Full Report Free →
SOC 2 CC9.2, HIPAA, PCI-DSS, and CMMC all require documented vendor due diligence — not just knowing the answer, but having audit-ready evidence you verified it. Most compliance teams can't produce that documentation on demand.
ThirdProof investigates Amazon Web Services across 27 intelligence sources in an average of 7 minutes — sanctions screening, cyber posture, SOC 2 verification, FedRAMP status, and more. Every investigation produces two deliverables: an audit-ready risk report and an auto-filled security questionnaire your prospects and auditors expect to see.
Replaces $600–$900 in manual compliance consulting time per vendor assessed.