- The core problem: how sensitive data can be sent to or generated by foundation models in Bedrock.
- Defensive strategies for Bedrock-enabled applications.
- How to implement input and output filtering and redaction.
- Expected results, a key takeaway, and next steps.
- Direct user input — a user pastes confidential text into the prompt.
- Retrieval-Augmented Generation (RAG) — a RAG pipeline performs a semantic query, retrieves document chunks, and inserts those chunks into the model context.
- Model output — the model echoes or generates sensitive information that originated in the prompt or the RAG context.

- GDPR — General Data Protection Regulation: https://gdpr.eu/
- HIPAA — U.S. Health Insurance Portability and Accountability Act: https://www.hhs.gov/hipaa/index.html
- PCI DSS — Payment Card Industry Data Security Standard: https://www.pcisecuritystandards.org/
- Minimize what you send. Only include the information required to perform the task. This reduces both token costs and the surface area for leaks.
- Mask or redact sensitive data. Detect patterns and fields (credit card numbers, national IDs, account numbers, email addresses, phone numbers, etc.) and redact them prior to sending to the model.
- Limit RAG retrieval scope and chunk size. Return only targeted snippets instead of whole documents to reduce exposing unrelated sensitive content.
- Enforce least privilege with IAM and access controls. Restrict which services, users, or roles can call specific models or access data stores.
- Validate and sanitize model outputs. Verify output formats (e.g., valid JSON) and apply post-generation filters to redact any leaked sensitive values.
Apply these measures both before calling Bedrock and after the model responds — do not depend solely on the model or a vendor to perform these protections for you.
A practical protection flow
- User input → Filter and redact sensitive or harmful content before storage or forwarding.
- RAG / Data retrieval → Filter and redact retrieved content before including it in the model prompt.
- Bedrock runtime → Call the model to generate the response.
- Validate and filter model response → Check format (for example, is this valid JSON?), required keys, and redact any leaked sensitive data.
- Deliver sanitized response → Return only the cleaned, validated content to the user.

- Redaction via pattern matching (simple example)
- Output validation (pseudo-code)
- Bedrock is a managed service hosting foundation models on AWS-managed infrastructure. Refer to the current AWS Bedrock documentation and service terms for the latest data usage commitments, but AWS does not use customer inference data to train the underlying foundation models.
- Data sent to Bedrock for inference stays within your AWS account boundary and the managed service workflow.
- Transport channels such as Direct Connect or VPN provide private connectivity into an AWS Region.
- Access to models is controlled by AWS IAM. Calls to a model without required permissions will fail.
- In-transit and at-rest encryption are used: TLS (HTTPS) and AWS encryption mechanisms protect data. Intercepted assets remain encrypted and unusable without keys.

Apply layered protections: minimize inputs, redact and mask sensitive data, scope RAG retrievals, validate outputs, and enforce least-privilege access. Your application must implement these safeguards both before and after calls to Bedrock.
- Implementing robust input/output filtering and redaction.
- Designing safe RAG pipelines with scoped retrieval and chunking strategies.
- Integrating IAM-based least-privilege access and secure networking.
- Bedrock documentation: https://docs.aws.amazon.com/bedrock (check the current AWS docs for up-to-date details)
- GDPR overview: https://gdpr.eu/
- HIPAA information: https://www.hhs.gov/hipaa/index.html
- PCI DSS: https://www.pcisecuritystandards.org/