Back to the registry
Agent passport

OpenAI - Bedrock Claude Migration Assessment — HIPAA + Cost Delta

Kriv AI · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownProfessional service
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Eight adjacent OpenAI → Bedrock assessment listings exist on AWS Marketplace today, and 100% of them hide behind "request private offer." Kriv's differentiator: published fixed-fee pricing + regulated-industry overlay (HIPAA eligibility delta, SR 11-7, NAIC, EU AI Act) + Anthropic CPN credibility + Claude-specific variant mapping.

Enterprises running OpenAI API in production face a predictable cluster of concerns: OpenAI data-retention and training-opt-out terms that trigger CISO / TPRM review; OpenAI API not HIPAA-eligible without Azure OpenAI BAA routing (Amazon Bedrock Claude IS HIPAA-eligible under AWS BAA); OpenAI contract renewal pressure with cost uncertainty; shadow AI on personal ChatGPT; unspent AWS Enterprise Discount Program (EDP) or Migration Acceleration Program (MAP) commitments; capability delta uncertainty (will Claude meet the existing use-case bar?); migration risk unknowns (prompt portability, model behavior differences). These concerns compound in regulated industries where HIPAA, SR 11-7, and NAIC Model Bulletin add eligibility + model-risk scrutiny.

Show the rest of the publisher’s description (5 more lines)

N38 is a 2–3 week fixed-fee assessment-only engagement that answers the decision: should we migrate OpenAI → Bedrock Claude, and if yes, how? Customer then engages Kriv's N36 Claude on Bedrock Migration for full implementation ($45K–$115K) or self-executes with Kriv's playbook. N38 is the natural pre-cursor; N36 is the execution.

Assessment methodology. OpenAI usage inventory (catalog every API call site per use case — model version (GPT-4o / o1 / o3 / GPT-5), prompt library, monthly token spend, p50/p95 latency, compliance constraints, data classification). Security + compliance review (data retention, training opt-out, HIPAA eligibility, sub-processor inventory, regional deployment, IP retention). Target-state mapping (recommend Claude variant per use case — Opus 4.6 for high-stakes reasoning, Sonnet 4.6 for 1M-context daily development + tool use, Haiku 4.5 for high-volume classification). Capability delta analysis (Claude vs OpenAI across tool use, vision, extended thinking, code generation, math reasoning, RAG grounding). Cost model (per-use-case monthly projection; AWS EDP / MAP burn; sensitivity bands; typical 20–50% savings for high-volume workloads — projection only). Risk assessment (prompt portability, model behavior, regression, rollback complexity). Staged migration plan (canary 1–5% → shadow → cutover → deprecate, with feature-flag rollback). Prompt-porting proof (Standard / Enterprise — XML structure + extended thinking + native tool use; side-by-side output). Bedrock Guardrails design starter (Enterprise — denied topics, content filters, PII redaction, contextual grounding; integrates with N28). Regulated-industry overlay (Enterprise — HIPAA, SR 11-7, NAIC, EU AI Act Article 25). CISO / TPRM vendor-exit dossier (Enterprise — rationale, risk mitigation, migration plan, governance handoff).

Reference architecture (target-state). Amazon Bedrock with Claude Opus 4.6 / Sonnet 4.6 / Haiku 4.5; Bedrock Model Invocation Logging → CloudWatch + S3 Object Lock; Bedrock Guardrails per use case; AWS PrivateLink (no public egress); AWS KMS customer-managed CMKs per data classification; AWS IAM Identity Center with MLOps / Data Scientist / AI Governance roles.

Three tiers. Foundation $15K (2 weeks; 1 use-case inventory + cost model + target Claude variant mapping + 10-page assessment report + 30-minute executive readout). Standard $25K (2.5 weeks; 3–5 use cases + full security + compliance review + capability delta analysis + cost model + migration plan + prompt-porting proof on 1 representative use case + Bedrock Guardrails design starter). Enterprise $35K (3 weeks; 10+ use cases + regulated-industry overlay HIPAA / SR 11-7 / NAIC / EU AI Act + full CISO / TPRM vendor-exit dossier + full migration plan + Bedrock Guardrails design starter + N36 implementation handoff). Optional Extra Use Case $8K each.

Important disclosures. Kriv does NOT execute the migration (N38 is assessment-only; migration execution is the separate N36 engagement). Kriv does NOT terminate OpenAI contracts (Customer procurement). No cost-savings guarantee (projection only). No capability-parity guarantee (model behavior varies). Kriv issues no certifications. No legal / regulatory / compliance advice. OpenAI / Anthropic API / Amazon Bedrock consumption separate. Anthropic CPN membership (April 9, 2026) — Kriv is a CPN partner, not an Anthropic-authorized reseller. Outcomes depend on representativeness of sample use cases provided by Customer during Week 1 inventory.

Highlights

Highlighted by the publisher on AWS Marketplace.

Fixed-fee $15K / $25K / $35K — 100% of 8+ competitors hide pricing behind "private offer." Adjacent Marketplace listings: Chaos Gears, AllCloud, SnapSoft, Avahi, Basis B.A.M. (Nova-powered free — undercuts on raw inventory but doesn't cover compliance), plus 3 others. Off-Marketplace: Classmethod 2-week $5K strategic insights + AI Clarity Guarantee. Kriv publishes — reduces procurement friction for fast-moving CISO / FinOps / CAIO buyers.

Regulated-industry overlay (HIPAA healthcare + SR 11-7 financial services + NAIC Model Bulletin insurance + EU AI Act Article 25 EU deployers) — unclaimed by any existing competitor listing. Covers HIPAA eligibility delta (Anthropic API direct is NOT HIPAA-eligible; Bedrock Claude IS). SR 11-7 model-risk overlay. NAIC Model Bulletin Pillar 2 (third-party AI). EU AI Act Article 25 downstream-provider obligations. Full CISO / TPRM vendor-exit dossier at Enterprise tier.

Anthropic CPN-certified (April 9, 2026) + Claude-specific variant mapping (Opus 4.6 / Sonnet 4.6 with 1M context / Haiku 4.5 per use case). 2–3 week turnaround. Natural pre-cursor to N36 Claude-on-Bedrock Migration ($45K–$115K implementation). Bedrock Guardrails design starter at Standard / Enterprise. Prompt-porting proof on 1 representative use case at Standard / Enterprise. N36 migration-execution handoff package at Enterprise. Extra Use Case $8K each.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyKriv AIAutomated
Websitehttps://www.kriv.ai/

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource

Publisher resources

3 links
Kriv AI Capabilities Overviewkriv.aiSource
Kriv AI on AWS Marketplace (Seller Profile)aws.amazon.comSource
Anthropic Claude Partner Networkwww.anthropic.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Professional service
Primary support contact. info@kriv.ai · +1-732-433-5564 · https://kriv.ai/support Response SLA. First response within 2 US business days (Mon–Fri 9 am – 6 pm ET, US federal holidays excluded). Active engagements: named Engagement Lead responds within 4 business hours weekdays. OpenAI contract-renewal-deadline assessments compress to same business day. Engagement onboarding. First customer contact within 2 US business days of marketplace inquiry / private-offer acceptance. Kickoff within 1 week of countersigned SOW. Escalation path. Engagement Lead (named in SOW) → Practice Director (info@kriv.ai) → CEO Abhinav Dangri (info@kriv.ai). Communication. Dedicated Microsoft Teams channel, weekly 60-minute video checkpoint, Friday written status note. Customer SMEs requested 3–5 hours/week (CISO, CAIO, Head of AI Platform, CIO, CTO, Head of FinOps, HIPAA Privacy Officer for healthcare, Head of TPRM, GC). Documentation handoff. Editable Word/Excel + PDF in your secure file share. OpenAI usage inventory + cost model as Excel; vendor security review + CISO/TPRM exit dossier as Word + PDF; capability delta + migration plan as Word; prompt-porting proof as Git repo + side-by-side output Excel; Bedrock Guardrails design starter as JSON; N36 handoff package as Word. Boundaries. Kriv does NOT execute the migration (N36 is separate); does NOT terminate OpenAI contracts; no cost-savings or capability-parity guarantee; issues no certifications; no legal / regulatory advice; no API stability guarantee. OpenAI API + Anthropic API + Amazon Bedrock + AWS consumption costs billed separately. Cost model is a projection, not a bill. Hours / holiday coverage. Mon–Fri 9 am – 6 pm ET. Closed on US federal holidays.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.