Amazon Web Services (AWS)
Global cloud infrastructure provider (IaaS/PaaS) delivering compute, storage, database, networking, AI and security services across 30+ regions.
Certifications & Accreditations
| Certification | Certifying Body | Scope | Achieved | Expiry | Status |
|---|---|---|---|---|---|
| ISO/IEC 27001:2022 | EY CertifyPoint | AWS global infrastructure and in-scope AWS services | — | — | Current |
| SOC 1 / SOC 2 / SOC 3 | Independent third-party auditor | In-scope AWS services; security, availability, confidentiality (SOC 2 Type II) | — | — | Current |
| PCI DSS v4.0 (Level 1 Service Provider) | Coalfire (QSA) | In-scope AWS services supporting cardholder data environments | — | — | Current |
| ISO/IEC 27017:2015 | EY CertifyPoint | Cloud-specific information security controls | — | — | Current |
| ISO/IEC 27018:2019 | EY CertifyPoint | Protection of personally identifiable information in public cloud | — | — | Current |
| ISO/IEC 27701:2019 | EY CertifyPoint | Privacy information management system (PIMS) | — | — | Current |
| ISO 22301:2019 | EY CertifyPoint | Business continuity management system | — | — | Current |
| ISO 9001:2015 | EY CertifyPoint | Quality management system for in-scope AWS services | — | — | Current |
| ISO/IEC 42001:2023 | EY CertifyPoint | AI management system for in-scope AI services | — | — | Current |
| CSA STAR Level 2 (CCM) | Cloud Security Alliance / third-party auditor | Cloud Controls Matrix self-assessment and certification | — | — | Current |
| FedRAMP (Moderate / High) | 3PAO, JAB / Agency authorised | AWS US East/West, GovCloud (US) and in-scope services | — | — | Current |
Compliance Frameworks
Penetration Testing
| Scope | Conducted By | Date | Frequency | Report |
|---|---|---|---|---|
| AWS infrastructure and in-scope services, assessed by independent auditors under the SOC 2, ISO 27001 and PCI DSS programmes (AWS does not publish individual test dates; date shown is the profile capture date) | Independent third-party auditors / AWS internal security assurance | Aug. 6, 2026 | Annual | On NDA |
| Customer-initiated penetration testing of the customer’s own AWS resources, permitted for listed services without prior approval (date shown is the profile capture date) | Customer or customer-appointed testing provider | Aug. 6, 2026 | Ad-hoc | Not Available |
Data Handling
Sub-processors
| Sub-processor | Purpose | Data Location | Trust Portal |
|---|---|---|---|
| Twilio, Inc. | A2P messaging for AWS End User Messaging and Amazon SNS | USA | View ↗ |
| Vonage Holdings Corp. (Nexmo Inc.) | A2P messaging and phone number validation | USA | — |
| Sinch Americas Inc. | A2P messaging | USA | — |
| Infobip Ltd. | A2P messaging | United Kingdom | — |
| TeleSign Corporation | A2P messaging and phone number validation | USA | — |
| Route Mobile (UK) Ltd | A2P messaging | United Kingdom | — |
| Cequens FZE | A2P messaging | United Arab Emirates | — |
| Tanla Digital Labs FZ-LLC | A2P messaging | United Arab Emirates | — |
| Meta Platforms, Inc. / Meta Platforms Ireland Ltd. | WhatsApp messaging for AWS End User Messaging | USA, Ireland | — |
| Environmental Systems Research Institute, Inc. (Esri) | Geolocation - maps and points of interest for Amazon Location Service | USA, Germany, Australia | — |
| HERE North America, LLC | Geolocation - maps and places for Amazon Location Service and AWS IoT Core | USA | — |
| Grabtaxi Holdings Pte Ltd | Geolocation - maps and places (device location feature) | Singapore | — |
| Key-Systems GmbH | Domain registration for Amazon Route 53 | Germany | — |
| 250ok Inc. / Email Data Source, Inc. | Email deliverability metrics for Amazon Pinpoint | USA, United Kingdom, Brazil | — |
Incident & Breach History
| Date | Summary | Impact | Resolution | Report |
|---|---|---|---|---|
| Nov. 25, 2020 | Amazon Kinesis Data Streams service event in the US-EAST-1 region caused by an operating system thread limit reached during capacity addition. | Elevated error rates for Kinesis and dependent services including CloudWatch, Cognito and EventBridge for several hours in a single region. | Thread configuration and capacity limits raised, front-end fleet re-architected onto larger hosts, and cellularisation work accelerated. | Report ↗ |
| Dec. 7, 2021 | Automated scaling activity in the AWS internal network of the US-EAST-1 region triggered congestion between the internal and main networks. | Degraded API availability and console access affecting many services in US-EAST-1 for approximately seven hours; global services homed in that region were also affected. | Scaling behaviour corrected, additional network configuration deployed, and Service Health Dashboard and support routing improved to be multi-region. | Report ↗ |
| June 13, 2023 | A latent defect in a subsystem responsible for capacity management for AWS Lambda caused elevated error rates in US-EAST-1. | Elevated error rates and latency for Lambda, and knock-on impact to services dependent on Lambda, for roughly three hours in a single region. | Defective subsystem behaviour remediated and additional safeguards plus monitoring added around capacity management. | Report ↗ |
Security Policies
| Policy | Availability | Link |
|---|---|---|
| AWS Shared Responsibility Model | Public | View ↗ |
| AWS Privacy Notice | Public | View ↗ |
| AWS Acceptable Use Policy | Public | View ↗ |
| AWS Security Bulletins (vulnerability advisories) | Public | View ↗ |
| AWS Risk and Compliance Whitepaper | Public | View ↗ |
| Compliance reports (SOC, ISO, PCI DSS) via AWS Artifact | On Request | View ↗ |
| AWS Data Processing Addendum and GDPR resources | Public | View ↗ |
Legal & Privacy
- Privacy Policy View ↗
- DPA Template View ↗
- Terms of Service View ↗
- GDPR Representative Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (EU/UK contracting entity). Data protection enquiries via aws.amazon.com/contact-us/data-privacy-inquiry/
- Lawful Basis Processor acting solely on documented customer instructions for customer content under the AWS DPA (Art. 28 GDPR). Performance of contract and legitimate interests for account information. International transfers rely on Standard Contractual Clauses and the AWS supplementary addendum.
Contact & Responsible Disclosure
- Security Contact [email protected]
- Responsible Disclosure View policy ↗
- Bug Bounty Platform HackerOne (AWS Vulnerability Disclosure Program); Amazon is a CVE Numbering Authority
Trust Portal & Audit Evidence
**Trust portal:** [AWS Artifact](https://aws.amazon.com/artifact/) - self-service portal for on-demand access to SOC 1/2/3 reports, ISO certificates, PCI DSS AoC, C5 and country-specific attestations. Most reports require acceptance of an NDA within the console.
**Public compliance index:** [AWS Compliance Programs](https://aws.amazon.com/compliance/programs/)
**Sub-processor list:** [aws.amazon.com/compliance/sub-processors](https://aws.amazon.com/compliance/sub-processors/) - AWS commits to updating this page at least 30 days before engaging a new sub-processor, with optional email notification.
**Status / availability:** [AWS Health Dashboard](https://health.aws.amazon.com/health/status)
Risk Assessment Notes
**Inherent risk drivers**
- Tier 1 / critical dependency for most hosting, storage and data processing workloads.
- Broad data categories possible, including personal and special category data, depending on customer configuration.
- Concentration risk: single-region designs (notably US-EAST-1) have historically been the source of the largest customer-visible outages.
**Mitigating factors**
- Extensive independent assurance: ISO 27001/27017/27018/27701/22301/42001, SOC 1-3, PCI DSS Level 1, FedRAMP, C5.
- Mature, versioned DPA with SCCs, documented sub-processor change notification and EU sovereign cloud option.
- Strong native security controls: KMS/CloudHSM, IAM, GuardDuty, CloudTrail, Config, Security Hub.
**Residual responsibilities for the customer (shared responsibility model)**
- Configuration hardening, IAM least privilege, patching of guest OS and applications.
- Region and data-residency selection, backup and DR design, multi-region resilience.
- Encryption key management decisions and logging/monitoring coverage.
**Suggested review cadence:** annual, with evidence refresh from AWS Artifact each time a SOC 2 report is reissued.
Copyright © 2026 SnapGRC