{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"amazon-web-services","name":"Amazon Web Services","domain":"aws.amazon.com","category":"Cloud and hosting","one_liner":"Amazon Web Services, Inc. (AWS) is a subsidiary of Amazon that provides on-demand cloud computing platforms and APIs to individuals","trust_center_url":"https://aws.amazon.com/","security_page_url":null,"url":"https://certreports.com/vendors/amazon-web-services/security","last_verified_at":"2026-09-21T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"ccpa","framework_name":"CCPA / CPRA","state":"vendor_stated","state_label":"Vendor-stated","sentence":"Vendor states an CCPA / CPRA privacy notice on custom as of 21 Sep 2026.","kind":null,"status_text":"Vendor states CCPA on its trust centre","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"custom","url":"https://certreports.com/vendors/amazon-web-services/security","evidence":[{"source_type":"trust_center","source_name":"Amazon Web Services trust centre (Custom)","url":"https://aws.amazon.com/","fetched_at":"2026-09-21 23:04:11.072743+00","content_hash":"e40667ef42c07c50455f51d5c75b92c21f5f93e2d6d29e5543a5a3f01c86b51c","wayback_url":null,"quote":"CCPA","confidence":1}]},{"framework":"dora-ctpp","framework_name":"DORA critical ICT provider designation","state":"verified_registry","state_label":"Verified","sentence":"Listed in the official registry as of 21 Sep 2026.","kind":"designation","status_text":"Designated critical ICT third-party provider under DORA Article 31 as Amazon web Services EMEA Sarl (ESAs list of 18 November 2025)","issued_at":"2025-11-18","expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-21","under_review":false,"source":"dora_ctpp","url":"https://certreports.com/vendors/amazon-web-services/security","evidence":[{"source_type":"registry","source_name":"ESAs list of designated critical ICT third-party providers","url":"https://www.eiopa.europa.eu/document/download/56b1ca78-5dd2-4d36-8377-47a538eb7558_en","fetched_at":"2026-09-21 22:18:15.023385+00","content_hash":"f010b04355106c2cb0183af15b0190f8804151f1eaa845cf7113452c42ade828","wayback_url":null,"quote":"Amazon web Services EMEA Sarl","confidence":1}]}],"brief":{"summary":"Amazon Web Services, a cloud and hosting vendor, states CCPA/CPRA on its trust centre as of 21 Sep 2026. No further scope detail accompanies the CCPA/CPRA claim as of 21 Sep 2026. Amazon Web Services is listed in the ESAs' DORA critical ICT third-party provider register as of 21 Sep 2026, designated under DORA Article 31 as Amazon Web Services EMEA Sarl. That DORA critical ICT provider designation was published on the ESAs' list of 18 Nov 2025. The CCPA/CPRA claim is a vendor statement, while the DORA critical ICT provider designation as of 21 Sep 2026 is a verified registry listing rather than a vendor claim.","bullets":["CCPA/CPRA: vendor-stated on trust centre, no scope detail captured (as of 21 Sep 2026).","DORA critical ICT provider designation: listed in the ESAs' register, published 18 Nov 2025, as Amazon Web Services EMEA Sarl.","Evidence set for Amazon Web Services covers two frameworks as of 21 Sep 2026: one vendor claim and one registry listing."],"model":"claude-sonnet-5 (subscription)","generated_at":"2026-09-22 10:07:27.049679+00"},"legal_docs":[],"documents":[],"statements":[],"security_profile":null,"regulations_url":"https://certreports.com/api/v1/vendors/amazon-web-services/regulations/{regulation}","subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-22T10:07:57.305Z"}