Amazon Bedrock is a fully managed service that provides secure, enterprise-grade access to foundation models to help build and scale generative AI applications. This directly matches the requirement for a fully managed service with secure, enterprise-grade access.
According to the Amazon Bedrock overview, Amazon Bedrock is a fully managed service that provides secure, enterprise-grade access to high-performing foundation models from leading AI companies to build and scale generative AI applications.
Under the AWS shared responsibility model for Amazon Bedrock, AWS is responsible for protecting the global infrastructure that runs the AWS Cloud, whereas the customer is responsible for maintaining control over their content and managing security configuration for the AWS services they use.
AWS strongly recommends never placing confidential or sensitive information (such as customer email addresses) into tags or free-form text fields (like Name fields). Any data entered into these fields may be utilized in billing or diagnostic logs.
Amazon Bedrock runs deep copies of the model provider's inference and training software in Model Deployment Accounts owned by the AWS service team. Third-party model providers have no access to these accounts, preventing them from seeing any prompts, completions, or logs.
Amazon Bedrock strictly requires the use of SSL/TLS to communicate with AWS resources, requiring at least TLS 1.2 and recommending TLS 1.3 for communications.
Under the AWS shared responsibility model for Amazon Bedrock, AWS protects the global infrastructure that runs the AWS Cloud, while customers are responsible for maintaining control of their hosted content and managing service security configurations.
AWS strongly recommends against putting confidential or sensitive information (such as customer email addresses) into tags or free-form text fields (like Name fields) because any data entered into these fields may be used in billing or diagnostic logs.
AWS requires a minimum of TLS 1.2 (and recommends TLS 1.3) for SSL/TLS communication with AWS resources. Furthermore, if FIPS 140-3 validated cryptographic modules are required when accessing AWS through a CLI or API, the customer must use a FIPS endpoint.
A company wants to develop a generative AI application but must adhere to strict security policies. They require a fully managed service that provides secure, enterprise-grade access to high-performing foundation models. Which AWS service should they choose to meet these requirements?
How confident are you in this answer?