# AWS Bedrock Guardrails vs Guard — 40° South

> Bedrock Guardrails protect models inside AWS. Guard produces independent Australian regulatory evidence for Bedrock calls, by proxy or by ingest.

[← All comparisons ](/compare) 

Compare

#  AWS Bedrock Guardrails vs Guard 

 Bedrock Guardrails protect models inside AWS. Guard produces independent Australian regulatory evidence for Bedrock calls, by proxy or by ingest. 

Why this comes up

If you run models on Amazon Bedrock, Bedrock Guardrails are the obvious built-in option. They filter harmful content, block denied topics, and redact a set of common PII entities. For a US-centric content-safety baseline, they work.

The gap for Australian regulated businesses is twofold. First, the PII set is generic: no Tax File Number, no Medicare number, no ABN, and none of the checksum validation those identifiers require. Second, Bedrock produces logs, not cryptographically signed per-call attestations mapped to APRA or the Privacy Act. Logs can be edited; a signed attestation cannot.

There’s also a supplier-risk angle. Under CPS 234 and CPS 230, AWS is a third-party (and potentially material) service provider. Relying on AWS’s own guardrails to evidence your oversight of AWS is exactly the gap APRA is pointing at. Guard provides an independent control layer in front of Bedrock.

The difference

Bedrock redacts a generic PII set inside AWS. Guard detects Australian identifiers and signs cryptographic evidence across every provider.

## Side by side

| Capability                                                   | Bedrock Guardrails | 40° South Guard |
| ------------------------------------------------------------ | ------------------ | --------------- |
| Content and harmful-topic filtering                          | ✓                  | \~              |
| Generic personal data redaction                              | ✓                  | ✓               |
| Australian personal data (TFN, Medicare, ABN) with checksums | ✗                  | ✓               |
| Prompt injection detection inside uploaded documents         | \~                 | ✓               |
| Per-call signed proof                                        | ✗                  | ✓               |
| CPS 234 / CPS 230 supplier-oversight evidence                | ✗                  | ✓               |
| Works across non-AWS providers                               | ✗                  | ✓               |
| Independent of the model host                                | ✗                  | ✓               |

✓ = supported · \~ = partial · ✗ = not supported 

Reflects publicly available information as at July 2026\. Tools change; check current vendor documentation. 

[ Download the full comparison (PDF) ](/downloads/guard-vs-bedrock.pdf) 

Could you run them together?

Yes. Keep Bedrock Guardrails on for content safety inside AWS, and run Guard in front of Bedrock so every call also produces independent, Australian-mapped, signed evidence.

The two layers do different jobs, and APRA’s third-party expectations are easier to meet when your oversight control isn’t owned by the supplier you’re overseeing.

## See Guard on your own AI calls 

Book a demo and we’ll show you a signed attestation for a real call, mapped to your obligations under CPS 234, the Privacy Act, and AI transparency. 

[Book a demo → ](/#get-started) [See all comparisons ](/compare)

---
Markdown version of https://40south.au/compare/bedrock for AI readers. Site index for LLMs: https://40south.au/llms.txt
