PrivateLink

AWS PrivateLink — private connectivity to services without traversing the public internet.

AWS PrivateLink creates interface VPC endpoints that route traffic to supported services over the AWS backbone instead of the public internet. Calling Amazon Bedrock or Amazon SageMaker from a VPC through a PrivateLink endpoint keeps sensitive request payloads — such as PII sent to a foundation model — off the public network, supporting compliance needs like HIPAA and SOC 2. The exam distinction: PrivateLink governs the network path, not who may call the service. IAM and resource-based policies still control authorization, so a private path alone does not stop an unauthorized principal from invoking Bedrock.

PlayPrepHQ study notes are written and reviewed against primary exam sources. How we create & review content →

Related terms

Back to Security, Compliance, and Governance for AI Solutions