Security8 min readOctober 5, 2026

Amazon Bedrock data retention modes: none, default or aws_review for business documents

What Amazon Bedrock's data retention modes actually change for the contracts and invoices you send to Claude, how the effective mode is resolved per Region and project, why some models refuse to run under none, how to lock the setting with an SCP, and how this compares with Amazon Q Business and BucketDesk Document AI.

JeVaughn Ferguson
Founder, developer
The short version

Bedrock's data retention mode is a per-Region, per-account choice between keeping nothing, following each model's policy, or allowing AWS to review content for up to 30 days, and the model you pick decides which of those is even possible. Set it deliberately in every Region you route to, pin it with an SCP, and remember that invocation logs and tools that build their own index keep copies the mode does not control.

Search interest in Amazon Bedrock data retention has risen several times over in the past six months. The reason is practical: Bedrock now asks you to choose a retention mode, some of the newest Claude models will not run until you do, and the first person to notice is usually whoever has to answer "where do our client documents go when someone asks the AI about them?"

This article explains the modes in terms of documents, not tokens: what is kept, by whom, for how long, and how to make sure nobody changes it without you knowing.

The four modes in plain terms

The setting is a single value called the data retention mode. None means zero data retention: no request or response data is written to durable storage by AWS. Default means the model's own policy applies, which for most models is no change from before; AWS may keep data for abuse detection. aws_review allows AWS to retain inputs and outputs for up to 30 days so that AWS staff can review them inside AWS, for models whose provider requires human review as a condition of access.

Inherit means no opinion at this level, and it is what new accounts and projects start with. A fifth value, provider_data_share, is legacy; AWS says it does not share content with model providers today, and in every mode the model provider does not receive your content.

  • none: nothing kept; models that require retention become unavailable.
  • default: the model's policy; AWS may keep data for abuse detection.
  • aws_review: kept up to 30 days inside AWS and reviewable by AWS, only for models that require it.
  • inherit: defer to the next scope up.

A permissive mode does not mean everything is kept

Each model declares the modes it accepts in a list called allowed_modes. Your mode sets what you permit; the model decides what actually happens. If a model accepts none, nothing is persisted for it even when your account is set to aws_review. If a model's minimum is aws_review, it only runs when your effective mode is aws_review or higher.

AWS currently names Claude Fable 5 and Claude Fable 5.1 as requiring aws_review. Under none or default they show as unavailable, and calls through bedrock-runtime fail with a ValidationException. Earlier Claude models, such as Claude Opus 4.8, accept none. So the real decision is which model your document assistant uses, and the retention mode follows from it.

How Bedrock decides the mode for a request

There are two scopes plus a fallback. A project setting applies to requests made through the newer bedrock-mantle endpoint under that project. The account setting applies to everything else in that Region. If both are inherit, the model's built-in default is used. The first value that is not inherit wins.

The setting is per Region and does not copy itself. An account set to none in us-east-1 is still at inherit in us-west-2. If you use cross-Region inference, retained data is stored in the Region that processed the request, so check the setting in every Region your inference profile can route to, not only the one you call.

# Account-level mode for bedrock-runtime calls in one Region
curl https://bedrock.us-east-1.amazonaws.com/data-retention \
  -H "Authorization: Bearer $AWS_BEARER_TOKEN_BEDROCK"

# A model's effective mode and the modes it accepts (bedrock-mantle)
curl https://bedrock-mantle.us-east-1.api.aws/v1/models/anthropic.claude-fable-5 \
  -H "x-api-key: $BEDROCK_API_KEY"
  • Repeat the check in each Region a cross-Region inference profile can use.
  • There is no console screen for this at launch; it is API or SDK only.
  • The control plane does not show per-model allowed_modes; the bedrock-mantle model endpoint does.

Locking the setting with an SCP

A retention mode that any developer can change is not a control. The write actions publish a condition key, so a Service Control Policy can pin the value for every account in an AWS Organization. The example denies setting anything other than none through the Bedrock control plane; add the equivalent bedrock-mantle actions (PutAccountDataRetention, CreateProject and UpdateProject) if you use that endpoint.

A middle path is to deny only aws_review and provider_data_share. That accepts default retention for abuse detection while ruling out human review, at the cost of not being able to use models that require it.

{
  "Effect": "Deny",
  "Action": ["bedrock:PutAccountDataRetention"],
  "Resource": "*",
  "Condition": {
    "StringNotEquals": { "bedrock:DataRetentionMode": "none" }
  }
}

Picking a mode for client and company documents

Our recommendation for anyone handling client files under NDA is simple: no retention. Set the mode to none in every Region you use, pin it with the SCP above, and choose a model whose allowed_modes includes none. The same goes for regulated records or anything with a contractual "no third-party retention" clause. A model you cannot use under none is a model those documents should not go to. If someone needs a model that requires review, set aws_review on a project for that team, not on the whole account, and write down who approved it.

For general internal documents, default is usually acceptable and keeps the most models available. Whatever you choose, the retention mode only covers inference. Bedrock logs you turn on yourself, such as model invocation logging to S3 or CloudWatch, keep full prompts for as long as you configure, so check those too.

  • Ask: are the files under NDA, or does any contract forbid retention by a processor? Then none.
  • Ask: do we need a model that requires review? Then aws_review on a project.
  • Ask: is invocation logging on? It keeps more than any retention mode.

How Amazon Q Business and BucketDesk compare

Amazon Q Business works differently. It crawls your data sources into its own index and answers from that copy, and it keeps conversation history until the conversation is deleted or goes inactive. Both are encrypted, with your own KMS key as an option, and AWS states Q Business does not use customer data to improve the service or its models. There is no retention mode to pick, but there is a standing second copy of your documents. Q Business is also no longer open to new customers; AWS points them to Amazon Quick.

BucketDesk Document AI calls Bedrock in your own AWS account, through the AI role you create, so your account's retention mode in that Region is the one that applies. Nothing is indexed ahead of time: the question and the one open document go to the model, and BucketDesk stores the chat's questions, answers and citations, encrypted, but not the document. A chat is removed about an hour after it ends, or after 30 days if you chose to keep it.

Document AI uses Amazon Nova Pro by default, and you can choose a different Bedrock model in its settings. That choice and your retention mode have to agree: if you pick a model that requires aws_review, such as Claude Fable 5, while your account is set to none or default, Bedrock rejects the request, so check the model's allowed_modes before switching.

  • Bedrock directly: you choose the mode and own every log.
  • Amazon Q Business: an index copy plus conversation history, no mode to choose, closed to new customers.
  • BucketDesk Document AI: your account's Bedrock mode, Amazon Nova Pro or a model you choose, no index, chat history kept for an hour or up to 30 days.
Try it in BucketDesk

Starter is free. Deploy a scoped role with CloudFormation, sign in, and browse, without handing anyone an access key.

Connect a bucket

Primary sources

Discussion

0 comments · open to guests · moderated
Comments appear after a quick review.

Liked this? Get the next article by email. No schedule, no filler, one click to leave.

Keep reading

All writing →