Security & Compliance

This page provides an overview of the security model used by Sandbox Studio. It explains how the solution is deployed, the controls in place, and how it aligns with enterprise security, compliance, and governance requirements.


Deployment Model


Data Protection


Identity & Access Management

IAM Roles
IAM Identity Center & SAML
Role-based Access

Network Security

Sandbox Studio backend services run inside a dedicated VPC with a layered subnet model to enforce isolation.


Core Security Services

AWS Key Management Service (KMS)
AWS WAF
Amazon CloudFront
Amazon RDS
AWS Lambda

Lifecycle Management


Logging, Monitoring & Governance


Compliance Alignment

While Sandbox Studio itself is not independently certified, it is built entirely on AWS services that hold stringent compliance certifications. This means Sandbox Studio inherits the trusted compliance foundation of AWS.

Key AWS Certifications in Scope

AWS services underpinning Sandbox Studio have been audited against major frameworks, including:

Compliance Certifications for Core Services
Service Certifications
Amazon CloudFront SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, ISO 27001/17/18, FedRAMP
AWS IAM Identity Center SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, IRAP, ISO 27001/17/18
AWS AppConfig SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, ISO 27001/17/18, FedRAMP
AWS Organizations SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, ISO 27001/17/18
Amazon RDS SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA/HITECH, ISO 27001/17/18, FedRAMP, GDPR
AWS Secrets Manager SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, ISO 27001/17/18, ISO 9001
AWS Lambda SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, FedRAMP, ISO 27001/17/18
AWS CodeBuild SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, FedRAMP, ISO 27001/17/18
Amazon S3 SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA/HITECH, ISO 27001/17/18, FedRAMP, GDPR
AWS Key Management Service (KMS) SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, FedRAMP, ISO 27001/17/18, FIPS 140-3
Amazon Simple Queue Service (SQS) SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, ISO 27001/17/18, FedRAMP
AWS Systems Manager SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, FedRAMP, ISO 27001/17/18
Amazon CloudWatch SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, FedRAMP, ISO 27001/17/18

For official audit reports and current scope, use AWS Artifact or consult the AWS Services in Scope by Compliance Program documentation.


Summary

Sandbox Studio is designed with security-first principles and built on compliant AWS services. Key assurances include:

This model provides security officers and auditors confidence that sandbox environments are isolated, compliant, and tightly governed — enabling safe innovation in AWS without introducing enterprise risk.


Revision #4
Created 2025-08-24 07:01:32 UTC by Andy
Updated 2025-08-27 09:44:26 UTC by Andy