Data protection in Amazon Bedrock changed AWS, Nov 15, 2024
AWS · Nov 15, 2024 · 4 added, 11 removed · found in an Internet Archive capture
- Added: Set up API and user activity logging with AWS CloudTrail. For information about using CloudTrail trails to capture AWS activities, see Working with CloudTrail trails in the AWS CloudTrail User Guide .
- Removed: Set up API and user activity logging with AWS CloudTrail.
- Added: If you require FIPS 140-3 validated cryptographic modules when accessing AWS through a command line interface or an API, use a FIPS endpoint. For more information about the available FIPS endpoints, see Federal Information Processing Standard (FIPS) 140-3 .
- Removed: If you require FIPS 140-2 validated cryptographic modules when accessing AWS through a command line interface or an API, use a FIPS endpoint. For more information about the available FIPS endpoints, see Federal Information Processing Standard (FIPS) 140-2 .
- Added: Amazon Bedrock doesn't store or log your prompts and completions. Amazon Bedrock doesn't use your prompts and completions to train any AWS models and doesn't distribute them to third parties.
- Added: Amazon Bedrock has a concept of a Model Deployment Account-in each AWS Region where Amazon Bedrock is available, there is one such deployment account per model provider. These accounts are owned and operated by the Amazon Bedrock service team. Model providers don't have any access to those accounts. After delivery of a model from a model provider to AWS, Amazon Bedrock will perform a deep copy of a model provider's inference and training software into those accounts for deployment. Because the model providers don't have access to those accounts, they don't have access to Amazon Bedrock logs or to customer prompts and completions.
- Removed: Amazon Bedrock doesn't use your prompts and continuations to train any AWS models or distribute them to third parties.
- Removed: Amazon Bedrock has a concept of a Model Deployment Account-in each AWS Region where Amazon Bedrock is available, there is one such deployment account per model provider. These accounts are owned and operated by the Amazon Bedrock service team. Model providers don't have any access to those accounts. After delivery of a model from a model provider to AWS, Amazon Bedrock will perform a deep copy of a model provider's inference and training container images into those accounts for deployment.
- Removed: Because the model providers don't have access to those accounts, they don't have access to Amazon Bedrock logs or to customer prompts and continuations. Amazon Bedrock doesn't store or log customer data in its service logs.
- Removed: Your training data isn't used to train the base Titan models or distributed to third parties. Other usage data, such as usage timestamps, logged account IDs, and other information logged by the service, is also not used to train the models.
- Removed: Amazon Bedrock uses the fine tuning data you provide only for fine tuning an Amazon Bedrock foundation model. Amazon Bedrock doesn't use fine tuning data for any other purpose, such as training base foundation models.
- Removed: Amazon Bedrock uses your training data with the CreateModelCustomizationJob action, or with the console , to create a custom model which is a fine tuned version of an Amazon Bedrock foundational model. Your custom models are managed and stored by AWS. By default, custom models are encrypted with AWS Key Management Service keys that AWS owns, but you can use your own AWS KMS keys to encrypt your custom models. You encrypt a custom model when you submit a fine tuning job with the console or programmatically with the CreateModelCustomizationJob action.
- Removed: None of the training or validation data you provide for fine tuning is stored in Amazon Bedrock accounts, once the fine tuning job completes. During training, your data exists in AWS Service Management Connector instance memory, but is encrypted on these machines using an XTS-AES-256 cipher that is implemented on a hardware module, on the instance itself.
- Removed: We don't recommend using confidential data to train a custom model as the model might generate inference responses based on that confidential data. If you use confidential data to train a custom model, the only way to prevent responses based on that data is to delete the custom model, remove the confidential data from your training dataset, and retrain the custom model.
- Removed: Custom model metadata (name and Amazon Resource Name) and a provisioned model's metadata is stored in an Amazon DynamoDB table that is encrypted with a key that the Amazon Bedrock service owns.
About this change
- Page
- docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html
- Kind
- Documentation
- Text hash
- 206161df2d7a to 12c4c5e97b37
- Dated by
- the first Internet Archive capture sampled that shows the new text; the change happened on or before this date