Back to the registry
Agent passport

Claude on Bedrock Migration & Security Review (CPN-Certified)

Kriv AI · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 3 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownProfessional service
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

First Anthropic CPN-certified Claude-on-Bedrock migration PS listing on AWS Marketplace in the US — Classmethod (Japan) is the only notable global competitor; the US regulated-industry market is wide open. Kriv's Anthropic Claude Partner Network certification (approved April 9, 2026) is the first-mover moat.

Fortune 1000 enterprises, AI-native Series C–E scale-ups, and regulated-industry operators (healthcare, life sciences, financial services, insurance) are moving production LLM workloads off OpenAI API, Azure OpenAI, Anthropic API direct, Google Gemini, and self-hosted Llama / Mistral to Claude on Amazon Bedrock. Drivers include OpenAI / Azure OpenAI data-residency + retention + training-opt-out concerns blocking CISO / TPRM review; HIPAA eligibility (Anthropic API direct is not HIPAA-eligible; Amazon Bedrock is, with AgentCore HIPAA-eligible since February 10, 2026); AWS Enterprise Discount Program (EDP) + Migration Acceleration Program (MAP) commitment burn; vendor consolidation; multi-region data residency; and cost optimization across Claude variants — Opus 4.6 (high-stakes reasoning + adjudication), Sonnet 4.6 (1M-context, daily development + tool use), and Haiku 4.5 (high-volume classification + summarization).

Show the rest of the publisher’s description (4 more lines)

Migration methodology. Discovery + inventory: catalog every production LLM call site across OpenAI / Azure OpenAI / Anthropic API direct / Gemini / Llama / Mistral, per use case — model version, prompt library, monthly token spend, p50/p95 latency, compliance constraints, data classification (PII / PHI / MNPI / public). Vendor security review: data residency, retention, training opt-out, HIPAA eligibility, subprocessors, regional deployment — feeds the CISO / TPRM vendor-exit dossier. Target-state mapping: route each workload to the optimal Claude variant on Bedrock (Opus 4.6, Sonnet 4.6 with 1M context, Haiku 4.5). Prompt portability + optimization: translate prompts to Claude idioms — XML structure, extended thinking blocks, native tool use, vision — and benchmark old vs new on identical test fixtures. Cost modeling: per-use-case projection across Opus 4.6 / Sonnet 4.6 / Haiku 4.5 vs incumbent, with AWS EDP / MAP commitment burn integrated and sensitivity bands. Bedrock Guardrails design: per-use-case denied topics, content filters, PII redaction, contextual grounding, prompt-injection filters (integrates with N28 for regulated Customers). Performance benchmarking: replay representative production test set; compare quality (LLM-as-judge + human-rated), latency, throughput, cost-per-successful-response. Migration execution: canary 1–5% → shadow parallel (no-serve) → cutover → deprecate, behind feature flags with instant rollback. Security + compliance review: CISO / TPRM / HIPAA Privacy Officer approval artifacts; regulated-industry overlay (HIPAA for healthcare, SR 11-7 for FS).

Reference architecture (target-state). Amazon Bedrock with Claude Opus 4.6 / Sonnet 4.6 / Haiku 4.5 in Customer AWS account; Bedrock Model Invocation Logging → CloudWatch + S3 Object Lock (WORM audit trail); Bedrock Guardrails per use case; AWS PrivateLink endpoint (no public egress); AWS KMS customer-managed CMKs per data classification; AWS IAM Identity Center with MLOps / Data Scientist / AI Governance roles.

Three tiers. Foundation $45K (3 weeks; single use case; vendor security review; cost model; Guardrails baseline; canary rollout; 30-day warranty). Standard $75K (4 weeks; 3–5 use cases; full CISO / TPRM exit dossier; full cost model with EDP / MAP burn; Guardrails per use case; shadow testing; CloudWatch + QuickSight cost-monitoring dashboards; 45-day warranty). Enterprise $115K (6 weeks; 10+ use cases; multi-account deployment via Control Tower; regulated-industry overlay — HIPAA for healthcare integrates E3 + N23, SR 11-7 for FS integrates N24; N26 + N27 + N28 + N29 + N31 sibling integration; 60-day hypercare). Optional Extra Use Case $15K each.

Important disclosures. Kriv does NOT terminate Customer vendor contracts (Customer procurement responsibility). No cost-savings guarantee (typical 20–50% vs OpenAI API for high-volume; actuals depend on usage). No quality-parity guarantee (model behavior varies; benchmarking produces evidence, not a guarantee). Kriv does NOT operate post-migration unless Managed Service retainer. Kriv issues no SOC 2 / HIPAA / HITRUST / ISO / FedRAMP certifications. No legal, regulatory, or compliance advice. AWS + Anthropic + Bedrock consumption costs are billed by AWS / Anthropic separately from Kriv fees. No Bedrock / Claude API stability guarantee — breaking changes may require Customer-side remediation. Anthropic CPN membership (April 9, 2026) — Kriv is a CPN partner, not an Anthropic-authorized reseller.

Highlights

Highlighted by the publisher on AWS Marketplace.

First CPN-certified Claude-on-Bedrock migration PS listing on AWS Marketplace in the US — Classmethod is JP-only; US regulated-industry market is wide open. Security-review-first methodology: vendor security review of incumbent stack (OpenAI / Azure OpenAI / Anthropic API direct / Gemini / Llama / Mistral) covering data residency / retention / training opt-out / HIPAA eligibility / subprocessors / regional deployment / IP retention — feeds CISO / TPRM vendor-exit dossier at Enterprise tier.

Claude-specific variant mapping — Opus 4.6 (high-stakes reasoning + adjudication), Sonnet 4.6 (1M context; daily development + tool use), Haiku 4.5 (high-volume classification + fast review + summarization) per use case. Cost model with AWS EDP / MAP burn integration — typical 20–50% savings potential vs OpenAI API for high-volume workloads (projection, not guarantee). Prompt portability + optimization with XML structure, extended thinking blocks, native tool use, vision support.

AWS Select + Databricks + Anthropic CPN-certified member (April 9, 2026; CPN partner, not Anthropic-authorized reseller) — 3–6 weeks, $45K / $75K / $115K. Canary (1–5%) → shadow (parallel, no-serve) → cutover → deprecate with feature-flag rollback. Enterprise tier integrates N26 MCP + N27 AgentCore + N28 Guardrails + N29 Red-Team + N31 Observability + N32 Control Tower Landing Zone siblings for full governed-Claude-on-Bedrock family. Amazon Bedrock AgentCore HIPAA-eligible Feb 10, 2026.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyKriv AIAutomated
Websitehttps://www.kriv.ai/

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource

Publisher resources

3 links
Kriv AI Capabilities Overviewkriv.aiSource
Kriv AI on AWS Marketplace (Seller Profile)aws.amazon.comSource
Anthropic Claude Partner Networkwww.anthropic.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Professional service
Primary support contact. info@kriv.ai · +1-732-433-5564 · https://kriv.ai/support Response SLA. First response within 2 US business days (Mon–Fri 9 am – 6 pm ET, US federal holidays excluded). Active engagements: named Engagement Lead responds within 4 business hours weekdays. Renewal-deadline-driven engagements compress to same business day. Engagement onboarding. First customer contact within 2 US business days of marketplace inquiry / private-offer acceptance. Kickoff within 1–2 weeks of countersigned SOW. Escalation path. Engagement Lead (named in SOW) → Practice Director (info@kriv.ai) → CEO Abhinav Dangri (info@kriv.ai). Communication. Dedicated Microsoft Teams channel, weekly 60-minute video checkpoint, Friday written status note. Customer SMEs requested 4–6 hours/week (CISO, CAIO, VP Engineering, HIPAA Privacy Officer, Head of FinOps, Head of Procurement, Head of TPRM, GC). Documentation handoff. Editable Word/Excel + PDF in your secure file share. LLM inventory + cost model as Excel; vendor security review + CISO/TPRM exit dossier as Word + PDF; prompt library as Git repo; Guardrails as JSON; Bedrock architecture as .drawio + PNG + CloudFormation / CDK. Boundaries. Kriv does NOT terminate Customer vendor contracts; no cost-savings or quality-parity guarantee; no post-migration operations unless Managed Service retainer; issues no certifications; no legal / regulatory advice; no Bedrock / Claude API stability guarantee. AWS + Anthropic + Bedrock consumption billed by AWS / Anthropic, separate from Kriv fees. Hours / holiday coverage. Mon–Fri 9 am – 6 pm ET. Closed on US federal holidays.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.