As both an Anthropic and AWS Partner, we are often asked this question.
What's the difference between running Claude directly with Anthropic or in AWS Bedrock?
It's the same model either way. What changes is whose infrastructure your data passes through, who can see it, and which security controls you get to use.
Where your data goes
Bedrock: Prompts and outputs stay inside AWS. Anthropic doesn't receive or see your Bedrock traffic, because AWS runs the model in its own accounts. Your data isn't used for training, and AWS doesn't keep a log of prompts or responses unless you turn on logging yourself.
Direct (Anthropic API): Your data goes to Anthropic's infrastructure. Commercial API data isn't used for training by default. Anthropic keeps it for a limited period, and content flagged for trust and safety review can be kept longer. Zero Data Retention is available under a contract.
Security controls
| |
Bedrock
|
Anthropic API
|
|
Sign-in
|
AWS IAM roles and policies, with short-lived credentials
|
API keys scoped to workspaces, plus SSO for the console
|
|
Network
|
Private connection from your own network (VPC PrivateLink), so traffic never touches the public internet
|
Public endpoint over TLS
|
|
Encryption keys
|
AWS KMS, including keys you manage yourself for logs and fine-tuning data
|
Keys managed by Anthropic
|
|
Audit logs
|
CloudTrail records every API call, and it plugs into the security tools you already use
|
Usage and admin logs through the Console and Admin API
|
|
Where data is processed
|
You pick the region. Cross-region inference can move requests between regions, but stays within one geography (US, EU, etc.)
|
More limited region choices
|
|
Content filtering
|
Bedrock Guardrails, with filters, PII redaction, and denied topics you configure
|
You build this yourself, or rely on the model's own behavior
|
|
Compliance
|
You inherit your AWS compliance scope: HIPAA under your existing AWS BAA, FedRAMP High and IL levels in GovCloud
|
Anthropic's own certifications (SOC 2 Type II, ISO 27001/42001), plus a HIPAA BAA if you sign one
|
The tradeoff
- Bedrock usually wins on governance for organizations already on AWS. The security review is shorter because nothing new crosses the trust boundary, there's no separate vendor data agreement, and the model is covered by your existing IAM, logging, and compliance setup.
- The direct API wins on features. New models, beta tools, and Anthropic-hosted features (code execution, web search, Files API, MCP connector) usually arrive there first. Some reach Bedrock later, and some never do. When you use features that Anthropic hosts, your data goes to Anthropic regardless of setup.
- Security isn't really better on either side. Both are enterprise-grade. The real question is whether your security team prefers "everything stays in our AWS account" or "we add Anthropic as a vetted vendor." Regulated industries (finance, healthcare, government) almost always pick the first.