As both an Anthropic and AWS Partner, we are often asked this question.
What's the difference between running Claude directly with Anthropic or in AWS Bedrock?
It's the same model either way. What changes is whose infrastructure your data passes through, who can see it, and which security controls you get to use.
Bedrock: Prompts and outputs stay inside AWS. Anthropic doesn't receive or see your Bedrock traffic, because AWS runs the model in its own accounts. Your data isn't used for training, and AWS doesn't keep a log of prompts or responses unless you turn on logging yourself.
Direct (Anthropic API): Your data goes to Anthropic's infrastructure. Commercial API data isn't used for training by default. Anthropic keeps it for a limited period, and content flagged for trust and safety review can be kept longer. Zero Data Retention is available under a contract.
|
Bedrock |
Anthropic API |
|
|
Sign-in |
AWS IAM roles and policies, with short-lived credentials |
API keys scoped to workspaces, plus SSO for the console |
|
Network |
Private connection from your own network (VPC PrivateLink), so traffic never touches the public internet |
Public endpoint over TLS |
|
Encryption keys |
AWS KMS, including keys you manage yourself for logs and fine-tuning data |
Keys managed by Anthropic |
|
Audit logs |
CloudTrail records every API call, and it plugs into the security tools you already use |
Usage and admin logs through the Console and Admin API |
|
Where data is processed |
You pick the region. Cross-region inference can move requests between regions, but stays within one geography (US, EU, etc.) |
More limited region choices |
|
Content filtering |
Bedrock Guardrails, with filters, PII redaction, and denied topics you configure |
You build this yourself, or rely on the model's own behavior |
|
Compliance |
You inherit your AWS compliance scope: HIPAA under your existing AWS BAA, FedRAMP High and IL levels in GovCloud |
Anthropic's own certifications (SOC 2 Type II, ISO 27001/42001), plus a HIPAA BAA if you sign one |