Skip to main content
security · aws

Amazon Bedrock guardrails with no sensitive information filter for PII

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags Amazon Bedrock guardrails whose `sensitiveInformationPolicy` provides no PII protection. Model calls protected only by such a guardrail can pass names, email addresses or account numbers straight through. ZopNight reads the guardrail's DRAFT version, raises this as a high-severity security finding and shows no dollar saving.

Signal and threshold

How ZopNight evaluates Amazon Bedrock guardrails with no sensitive information filter for PII.
Field Value
Rule IDsRC-1615
Categorysecurity
Severityhigh
Metricnone — pure configuration read
ThresholdPII protection not configured in the sensitive information policy
SourceZopNight
Permissions usedbedrock:ListGuardrails · bedrock:GetGuardrail

What a sensitive information filter does

Bedrock Guardrails can detect personally identifiable information in prompts and responses using sensitive information filters. You choose from built-in PII types, such as names, addresses and ages, and can add your own regex patterns. For each one you pick a mode: Block, which rejects the whole request or response and returns your configured message, or Mask, which replaces the detected value with its type, for example {NAME}. A guardrail without this filter can still block topics or harmful content, but it lets personal data through untouched.

Inspecting a guardrail’s PII settings

Terminal window
aws bedrock list-guardrails --query 'guardrails[].[id,name,version,status]' --output table
aws bedrock get-guardrail --guardrail-identifier gr-abc123 \
--query 'sensitiveInformationPolicy'

An empty or missing sensitiveInformationPolicy means there are no PII entities and no regexes. GetGuardrail returns the DRAFT version when you do not pass --guardrail-version; add it to check a published version.

What triggers the finding

ZopNight reads each guardrail’s configuration and records whether PII protection is enabled. The finding fires only when that record says it is disabled. It is a configuration check with no metric or window.

Gaps in what ZopNight can see

If the configuration read did not happen, ZopNight raises nothing. The read uses the DRAFT version, which is the working copy and normally at least as protective as anything published. When applications are pinned to an older published version, what is live can differ from the DRAFT, so the finding describes the working copy. Check which version your applications actually call.

Risk rather than savings

There is no dollar saving here. The exposure is personal data in prompts, retrieved documents or model output reaching logs, users or other systems without redaction, which can breach privacy obligations.

Adding PII protection

  1. Open the guardrail in the Bedrock console and add a sensitive information filter with the PII types your workload handles, plus regexes for internal identifiers.
  2. Choose Block for data that must never appear, or Mask where the rest of the text is still useful.
  3. Publish a new version, since applications should call a numbered version rather than DRAFT: aws bedrock create-guardrail-version --guardrail-identifier gr-abc123
  4. Point agents and applications at the new version number.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·