Bedrock AgentCore

Operated by Amazon Web Services · Enterprise Agents
Documentation reviewed

Managed runtime for deploying and scaling AI agents on AWS.

Operator
Amazon Web Services
Open source
Not indicated
Payment capability
Not indicated
Supports MCP
Yes
Supports agent-to-agent protocols
Yes
Enterprise-managed
Yes
Cryptographically signed
Not indicated
Independent audit on record
Yes — see source
Operator confirmed this listing
Not indicated
Last reviewed
2026-09-08
Verification notes: Correction this pass: the audited flag moves from false to true. AWS's own Bedrock AgentCore developer guide has a dedicated compliance-validation page that names AgentCore specifically (not AWS generally) as SOC 2, ISO/IEC 27001:2022, and CSA STAR compliant, plus HIPAA eligible and FedRAMP Class C/Class D compliant, with third-party audit reports downloadable via AWS Artifact. This is a narrower and more specific claim than the org-wide certification language that has kept other listings' audited flags at false in past passes (compare ChatGPT Agent, where OpenAI's certifications weren't confirmed to name that specific agent feature) — the same reasoning that flipped Copilot Studio's audited flag once its ISO/IEC 42001 scope was confirmed to explicitly include that product. evidenceLevel stays at documentation-reviewed rather than moving to independently-audited, since this site sourced the claim from AWS's own compliance page rather than reviewing an actual audit report. Prior correction, still standing: the a2a flag moved from false to true after AWS's own Machine Learning blog ('Introducing agent-to-agent protocol support in Amazon Bedrock AgentCore Runtime,' published November 11, 2025, updated July 10, 2026) documented AgentCore Runtime acting as a transparent A2A proxy — containers run stateless, streamable HTTP servers on port 9000, JSON-RPC payloads pass through unmodified, and agent discovery works via the standard /.well-known/agent-card.json Agent Card. GA since October 2025 and MCP support (stateful/stateless servers, OAuth/IAM Gateway) are unchanged.

Suggest a correction to this profile →