Data protection in Amazon Bedrock changed AWS, May 28, 2024
AWS · May 28, 2024 · 3 added, 3 removed · found in an Internet Archive capture
- Added: Amazon Bedrock has a concept of a Model Deployment Account-in each AWS Region where Amazon Bedrock is available, there is one such deployment account per model provider. These accounts are owned and operated by the Amazon Bedrock service team. Model providers don't have any access to those accounts. After delivery of a model from a model provider to AWS, Amazon Bedrock will perform a deep copy of a model provider's inference and training container images into those accounts for deployment.
- Added: Because the model providers don't have access to those accounts, they don't have access to Amazon Bedrock logs or to customer prompts and continuations. Amazon Bedrock doesn't store or log customer data in its service logs.
- Removed: Each model provider has an escrow account that they upload their models to. The Amazon Bedrock inference account has permissions to call these models, but the escrow accounts themselves don't have outbound permissions to Amazon Bedrock accounts. Additionally, model providers don't have access to Amazon Bedrock logs or access to customer prompts and continuations.
- Removed: Amazon Bedrock doesn't store or log your data in its service logs.
- Added: Amazon Bedrock uses your training data with the CreateModelCustomizationJob action, or with the console , to create a custom model which is a fine tuned version of an Amazon Bedrock foundational model. Your custom models are managed and stored by AWS. By default, custom models are encrypted with AWS Key Management Service keys that AWS owns, but you can use your own AWS KMS keys to encrypt your custom models. You encrypt a custom model when you submit a fine tuning job with the console or programmatically with the CreateModelCustomizationJob action.
- Removed: Bedrock uses your training data with the CreateModelCustomizationJob action, or with the console , to create a custom model which is a fine tuned version of an Amazon Bedrock foundational model. Your custom models are managed and stored by AWS. By default, custom models are encrypted with AWS Key Management Service keys that AWS owns, but you can use your own AWS KMS keys to encrypt your custom models. You encrypt a custom model when you submit a fine tuning job with the console or programmatically with the CreateModelCustomizationJob action.
About this change
- Page
- docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html
- Kind
- Documentation
- Text hash
- f92bec0a4d99 to 206161df2d7a
- Dated by
- the first Internet Archive capture sampled that shows the new text; the change happened on or before this date