{
  "fixes": {
    "slug": "amazon-nova-embeddings",
    "name": "Amazon Nova Multimodal Embeddings",
    "listing": "https://www.anchorterminal.com/tools/amazon-nova-embeddings",
    "markdown": "# Fix list: Amazon Nova Multimodal Embeddings\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/amazon-nova-embeddings, the October 2026 research run, assessed 8 October 2026. Grade BB, 75 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Amazon Nova Multimodal Embeddings: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Payments \u0026 pricing, 30 out of 100, up to 8.8 more on the total\n\nWhy it scored 30: No x402, MPP or L402 (0). Per-token, per-image and per-second prices are public without a login. The table is drawn by script, so the figures come from the price feed the page loads (20). No model-specific free tier. The Free Tier FAQ says new accounts receive up to $200 in credits and that most new customers need no payment method, though AWS may ask for one, so half, as on the other AWS listings (10). A person signs up for an AWS account in a browser (0).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 2. Maintenance \u0026 community, 50 out of 100, up to 4.4 more on the total\n\nWhy it scored 50: Model reading. No dated change to the model was found after its launch on 28 October 2025, 345 days before this check. The GovCloud Region and the batch rows are undated (0). The Bedrock document history has three platform entries in the last 90 days (21 and 29 September and 6 October 2026), none about this model, and the lifecycle policy gives at least 12 months of availability and 6 months of Legacy notice (15 of 20). Public document histories, re:Post and AWS Support, with no model release notes (10 of 15). Current official SDKs, `boto3` 1.43.109 on 7 October 2026 and `@aws-sdk/client-bedrock-runtime` 3.1148.0 (15). The SDKs ship on AWS's release train and `boto3` supports Python 3.10 and later (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## 3. Schema \u0026 documentation, 76 out of 100, up to 3.9 more on the total\n\nWhy it scored 76: Model reading. `InvokeModel` and `StartAsyncInvoke` are in the published AWS service models, but the request body is an opaque document there, and the embedding schema exists only as prose in the Nova guide (15 of 25). The Nova guide has an llms.txt and Markdown copies of both embedding pages (10). The schema page says which `embeddingPurpose` to use for indexing and for each retrieval type, with a worked example (17 of 20). Every field is listed with type, allowed values, default and required status (13 of 15). Python examples for synchronous and asynchronous calls and the S3 output layout are given. Errors are the general Bedrock list, and the Bedrock model card contradicts the guide by marking Invoke as unsupported and showing a sample with an empty `modelInput` (9 of 15). A `schemaVersion` field, a versioned model ID and a dated document history, though the same content sits in two guides (12 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 4. Agent ergonomics, 78 out of 100, up to 3.6 more on the total\n\nWhy it scored 78: Model reading. Four output sizes from 256 to 3072, default 3072. No binary or integer output type was found in the schema (18 of 25). A synchronous request embeds one input, so indexing many small items needs many calls, a batch job or the asynchronous API, which segments long text, audio and video (12 of 20). Typed exceptions with HTTP codes and a troubleshooting page, plus `truncatedCharLength` in the response when text was cut. No embedding-specific error guidance (16 of 20). Synchronous calls are stateless and asynchronous jobs take an idempotency token (20). `embeddingPurpose` and `truncationMode` are required, asynchronous calls need an S3 bucket, and requests need SigV4 or a Bedrock API key. AWS SDKs cover Python, JavaScript and other languages (12 of 15).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 5. Transparency \u0026 trust, 79 out of 100, up to 1.8 more on the total\n\nMade of editorial 69, provenance 88.\n\nWhy it scored 79: Closed model under the AWS Service Terms, with Apache-2.0 SDKs (15). The abuse-detection page, the data-protection page and section 50.12 of the Service Terms agree that Bedrock stores no inputs or outputs by default and that model providers cannot see them. The data-retention page describes its modes for the Messages, Chat Completions and Responses APIs and doesn't name `InvokeModel`, and the DPA and sub-processor list were not read in this run (22 of 30). The lifecycle policy for models launched before 7 September 2026 promises 12 months on Bedrock and a Legacy period of at least 6 months, and the model card dates the earliest end of life at 28 October 2026 (20). The card lists the two Regions and in-Region processing only. Sub-processors were not checked (12 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Terms of service: read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points (3.1 of 10)\n- security.txt: published but past its Expires date (5 of 10)\n\n## 6. Security \u0026 auth, 91 out of 100, up to 1.6 more on the total\n\nWhy it scored 91: Model reading. IAM with SigV4, roles and temporary credentials, or Bedrock API keys, where short-term keys expire within 12 hours and inherit the caller's permissions. Keys travel in the Authorization header (30). Bedrock states zero data retention and zero operator access by default, this model is not on the list of models whose traffic is stored for abuse detection, and Bedrock is not among the services whose content AWS uses for improvement under section 50.3 of the Service Terms. Image inputs flagged as apparent CSAM may be stored and reviewed (18 of 20). The model returns vectors only (10 of 15). CloudTrail logs `InvokeModel` as a management event and `StartAsyncInvoke` as a data event, and API keys are not logged (15). A vulnerability disclosure programme on HackerOne and Amazon Bedrock in SOC scope on the list updated 11 August 2026. The security.txt on aws.amazon.com expired on 24 September 2026 and no paid bounty was found (18 of 20).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 7. Reliability, 95 out of 100, up to 1 more on the total\n\nWhy it scored 95: Hosted reading. AWS Health Dashboard with per-service, per-Region history and RSS feeds (20). The Bedrock us-east-1 feed was empty on 8 October 2026 and the dashboard history lists no Bedrock event in us-east-1 since a model access event on 13 June 2026, outside the 90-day window. The public dashboard records broad events only, and the model runs in one commercial Region with no cross-Region profile, so 25 of 30 is our call. Quotas are published, 2,000 requests a minute and 30 concurrent asynchronous requests (15). The troubleshooting page maps `ThrottlingException` to 429 and advises exponential backoff with jitter, and `StartAsyncInvoke` takes a `clientRequestToken` (15). The Bedrock SLA, last updated 4 October 2023, commits to 99.9 per cent a month per Region for the Bedrock APIs for models (10). Announced as generally available on 28 October 2025 (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- Whether `InvokeModel` works for this model today. The Nova guide documents it and the Bedrock model card marks Invoke as unsupported. No call was made.\n- Whether the model has changed since 28 October 2025. No release notes for it were found, and the GovCloud Region and batch pricing are undated.\n- Which languages the model supports. No language list was found in the two embedding pages.\n- Whether the data-retention modes apply to `InvokeModel` and `StartAsyncInvoke`. The page names the Messages, Chat Completions and Responses APIs.\n- The lead gave the range as 256 to 3072 dimensions. The model accepts only 256, 384, 1024 and 3072.\n- unchecked: the AWS DPA and sub-processor list, the AWS Customer Agreement and the AWS privacy notice were not read in this run\n- unchecked: the AI service card for the model, and the AWS News blog post linked from the announcement\n\n## Weaknesses\n\n- In-Region inference in us-east-1 and us-gov-west-1 only, with no cross-Region inference profile\n- A synchronous request embeds one item, with at most 8,192 characters of inline text or 30 seconds of audio or video\n- The Bedrock model card marks Invoke as unsupported while the Nova guide documents `InvokeModel` for synchronous calls\n- No dated change to the model was found after its launch on 28 October 2025\n- Both quotas are marked not adjustable through Service Quotas\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- Call `bedrock-runtime` in us-east-1 with model ID `amazon.nova-2-multimodal-embeddings-v1:0`. No other commercial Region serves it\n- Index with `embeddingPurpose` `GENERIC_INDEX`, then embed queries with the retrieval value that matches the index, such as `TEXT_RETRIEVAL` or `GENERIC_RETRIEVAL`\n- Always send `truncationMode` with text. It is required, and `NONE` fails the request when the text is too long\n- Use `StartAsyncInvoke` with an S3 output bucket for anything over 30 seconds or 8,192 characters, and pass `clientRequestToken` so a retry doesn't start a second job\n- Keep one `embeddingDimension` per index. The default is 3072\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "BB",
    "score": 75,
    "assessed": "2026-10-08",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 30,
        "maxGain": 8.8,
        "reason": "No x402, MPP or L402 (0). Per-token, per-image and per-second prices are public without a login. The table is drawn by script, so the figures come from the price feed the page loads (20). No model-specific free tier. The Free Tier FAQ says new accounts receive up to $200 in credits and that most new customers need no payment method, though AWS may ask for one, so half, as on the other AWS listings (10). A person signs up for an AWS account in a browser (0).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 50,
        "maxGain": 4.4,
        "reason": "Model reading. No dated change to the model was found after its launch on 28 October 2025, 345 days before this check. The GovCloud Region and the batch rows are undated (0). The Bedrock document history has three platform entries in the last 90 days (21 and 29 September and 6 October 2026), none about this model, and the lifecycle policy gives at least 12 months of availability and 6 months of Legacy notice (15 of 20). Public document histories, re:Post and AWS Support, with no model release notes (10 of 15). Current official SDKs, `boto3` 1.43.109 on 7 October 2026 and `@aws-sdk/client-bedrock-runtime` 3.1148.0 (15). The SDKs ship on AWS's release train and `boto3` supports Python 3.10 and later (10).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 76,
        "maxGain": 3.9,
        "reason": "Model reading. `InvokeModel` and `StartAsyncInvoke` are in the published AWS service models, but the request body is an opaque document there, and the embedding schema exists only as prose in the Nova guide (15 of 25). The Nova guide has an llms.txt and Markdown copies of both embedding pages (10). The schema page says which `embeddingPurpose` to use for indexing and for each retrieval type, with a worked example (17 of 20). Every field is listed with type, allowed values, default and required status (13 of 15). Python examples for synchronous and asynchronous calls and the S3 output layout are given. Errors are the general Bedrock list, and the Bedrock model card contradicts the guide by marking Invoke as unsupported and showing a sample with an empty `modelInput` (9 of 15). A `schemaVersion` field, a versioned model ID and a dated document history, though the same content sits in two guides (12 of 15).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 78,
        "maxGain": 3.6,
        "reason": "Model reading. Four output sizes from 256 to 3072, default 3072. No binary or integer output type was found in the schema (18 of 25). A synchronous request embeds one input, so indexing many small items needs many calls, a batch job or the asynchronous API, which segments long text, audio and video (12 of 20). Typed exceptions with HTTP codes and a troubleshooting page, plus `truncatedCharLength` in the response when text was cut. No embedding-specific error guidance (16 of 20). Synchronous calls are stateless and asynchronous jobs take an idempotency token (20). `embeddingPurpose` and `truncationMode` are required, asynchronous calls need an S3 bucket, and requests need SigV4 or a Bedrock API key. AWS SDKs cover Python, JavaScript and other languages (12 of 15).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 79,
        "maxGain": 1.8,
        "reason": "Closed model under the AWS Service Terms, with Apache-2.0 SDKs (15). The abuse-detection page, the data-protection page and section 50.12 of the Service Terms agree that Bedrock stores no inputs or outputs by default and that model providers cannot see them. The data-retention page describes its modes for the Messages, Chat Completions and Responses APIs and doesn't name `InvokeModel`, and the DPA and sub-processor list were not read in this run (22 of 30). The lifecycle policy for models launched before 7 September 2026 promises 12 months on Bedrock and a Legacy period of at least 6 months, and the model card dates the earliest end of life at 28 October 2026 (20). The card lists the two Regions and in-Region processing only. Sub-processors were not checked (12 of 20).",
        "blend": "editorial 69, provenance 88",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 91,
        "maxGain": 1.6,
        "reason": "Model reading. IAM with SigV4, roles and temporary credentials, or Bedrock API keys, where short-term keys expire within 12 hours and inherit the caller's permissions. Keys travel in the Authorization header (30). Bedrock states zero data retention and zero operator access by default, this model is not on the list of models whose traffic is stored for abuse detection, and Bedrock is not among the services whose content AWS uses for improvement under section 50.3 of the Service Terms. Image inputs flagged as apparent CSAM may be stored and reviewed (18 of 20). The model returns vectors only (10 of 15). CloudTrail logs `InvokeModel` as a management event and `StartAsyncInvoke` as a data event, and API keys are not logged (15). A vulnerability disclosure programme on HackerOne and Amazon Bedrock in SOC scope on the list updated 11 August 2026. The security.txt on aws.amazon.com expired on 24 September 2026 and no paid bounty was found (18 of 20).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 95,
        "maxGain": 1,
        "reason": "Hosted reading. AWS Health Dashboard with per-service, per-Region history and RSS feeds (20). The Bedrock us-east-1 feed was empty on 8 October 2026 and the dashboard history lists no Bedrock event in us-east-1 since a model access event on 13 June 2026, outside the 90-day window. The public dashboard records broad events only, and the model runs in one commercial Region with no cross-Region profile, so 25 of 30 is our call. Quotas are published, 2,000 requests a minute and 30 concurrent asynchronous requests (15). The troubleshooting page maps `ThrottlingException` to 429 and advises exponential backoff with jitter, and `StartAsyncInvoke` takes a `clientRequestToken` (15). The Bedrock SLA, last updated 4 October 2023, commits to 99.9 per cent a month per Region for the Bedrock APIs for models (10). Announced as generally available on 28 October 2025 (10).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      }
    ],
    "provenance": [
      {
        "label": "Terms of service",
        "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
        "points": 3.1,
        "max": 10
      },
      {
        "label": "security.txt",
        "value": "published but past its Expires date",
        "points": 5,
        "max": 10
      }
    ],
    "unchecked": [
      "Whether `InvokeModel` works for this model today. The Nova guide documents it and the Bedrock model card marks Invoke as unsupported. No call was made.",
      "Whether the model has changed since 28 October 2025. No release notes for it were found, and the GovCloud Region and batch pricing are undated.",
      "Which languages the model supports. No language list was found in the two embedding pages.",
      "Whether the data-retention modes apply to `InvokeModel` and `StartAsyncInvoke`. The page names the Messages, Chat Completions and Responses APIs.",
      "The lead gave the range as 256 to 3072 dimensions. The model accepts only 256, 384, 1024 and 3072.",
      "unchecked: the AWS DPA and sub-processor list, the AWS Customer Agreement and the AWS privacy notice were not read in this run",
      "unchecked: the AI service card for the model, and the AWS News blog post linked from the announcement"
    ],
    "weaknesses": [
      "In-Region inference in us-east-1 and us-gov-west-1 only, with no cross-Region inference profile",
      "A synchronous request embeds one item, with at most 8,192 characters of inline text or 30 seconds of audio or video",
      "The Bedrock model card marks Invoke as unsupported while the Nova guide documents `InvokeModel` for synchronous calls",
      "No dated change to the model was found after its launch on 28 October 2025",
      "Both quotas are marked not adjustable through Service Quotas"
    ],
    "agentNotes": [
      "Call `bedrock-runtime` in us-east-1 with model ID `amazon.nova-2-multimodal-embeddings-v1:0`. No other commercial Region serves it",
      "Index with `embeddingPurpose` `GENERIC_INDEX`, then embed queries with the retrieval value that matches the index, such as `TEXT_RETRIEVAL` or `GENERIC_RETRIEVAL`",
      "Always send `truncationMode` with text. It is required, and `NONE` fails the request when the text is too long",
      "Use `StartAsyncInvoke` with an S3 output bucket for anything over 30 seconds or 8,192 characters, and pass `clientRequestToken` so a retry doesn't start a second job",
      "Keep one `embeddingDimension` per index. The default is 3072"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
