generated: '2026-09-18' method: searched source: >- smithy/dynamodb-2012-08-10.json (AWS first-party model), https://aws.amazon.com/compliance/programs/, https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/, well-known/amazon-dynamodb-well-known.yml (live probe 2026-09-18) note: >- Reward-only. DynamoDB is a proprietary NoSQL data store; the operational-database market has no bilateral API standard of the SCIM/FHIR/OData kind, so no domain standard is claimed and none is invented. What the contract DOES declare about itself - SigV4, awsJson1_0, PartiQL, Smithy - is recorded with the evidence. standards: - id: oauth2 conforms: false evidence: No oauth2 security scheme anywhere in the first-party model; authorization is IAM policy evaluated against a SigV4-signed request. - id: oidc conforms: false evidence: /.well-known/openid-configuration returned 404 on all five probed hosts (well-known/amazon-dynamodb-well-known.yml). - id: aws-sigv4 conforms: true evidence: 'aws.auth#sigv4 trait on the service shape, name "dynamodb" (smithy/dynamodb-2012-08-10.json).' - id: awsjson1_0 conforms: true evidence: 'aws.protocols#awsJson1_0 trait on the service shape; confirmed live - a 2026-09-18 probe returned content-type application/x-amz-json-1.0.' - id: smithy-idl conforms: true evidence: >- AWS publishes the DynamoDB contract as a Smithy 2.0 JSON AST at github.com/aws/api-models-aws - 58 operations, 270 structures, 35 modeled error shapes, plus a separate 4-operation DynamoDB Streams model. - id: partiql conforms: true evidence: >- ExecuteStatement, BatchExecuteStatement and ExecuteTransaction accept PartiQL - the SQL-compatible query language published as an open specification at partiql.org - as a first-class request surface alongside the native API. docs: https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/ql-reference.html - id: rfc9457-problem-details conforms: false evidence: 'Errors are {"__type":...,"message":...} under application/x-amz-json-1.0, not application/problem+json. Confirmed on a live 400 on 2026-09-18.' - id: rfc7232-conditional-requests conforms: false evidence: No ETag or If-Match anywhere in the model; concurrency is expressed as a ConditionExpression inside the request body. - id: json-api conforms: false evidence: RPC over POST / with X-Amz-Target; no resource URLs. - id: pagination conforms: true evidence: 'ExclusiveStartKey/LastEvaluatedKey cursors with the smithy.api#paginated trait on 6 operations (Query, Scan, ListTables, ListContributorInsights, ListExports, ListImports).' - id: idempotency conforms: partial evidence: >- smithy.api#idempotencyToken on 4 of 31 mutating operations (TransactWriteItems, ExecuteTransaction, ExportTableToPointInTime, ImportTable) with a documented 10-minute window; see conventions/amazon-dynamodb-conventions.yml idempotency.coverage = partial. - id: rfc8594-sunset-header conforms: false evidence: No Sunset or Deprecation header; no operation carries the smithy.api#deprecated trait. - id: rfc9116-security-txt conforms: true evidence: 'https://aws.amazon.com/.well-known/security.txt returned 200 on 2026-09-18 with Policy, Contact, Preferred-Languages, Encryption and Expires fields (well-known/amazon-dynamodb-security.txt).' - id: fhir-r4 conforms: false - id: scim conforms: false - id: odata conforms: false - id: psd2 conforms: false domain_standard: applicable: false note: >- Operational NoSQL databases have no adopted cross-vendor API standard - there is no database equivalent of SCIM or FHIR, and the nearest thing, a SQL dialect, DynamoDB meets halfway through PartiQL (recorded above as a real conformance, not as a domain standard). DynamoDB is not penalised for the absence and none is invented here. compliance_program: published: true url: https://aws.amazon.com/compliance/programs/ service_in_scope_url: https://aws.amazon.com/compliance/services-in-scope/ certifications: - SOC 1 - SOC 2 - SOC 3 - ISO 27001 - ISO 27017 - ISO 27018 - PCI DSS Level 1 - HIPAA eligible - FedRAMP (Moderate and High) - IRAP - MTCS - C5 - GDPR (AWS as processor) note: >- The certifications are AWS-wide programs under which DynamoDB is an in-scope service, not DynamoDB-specific audits. Recorded that way deliberately: the artefact a buyer needs is the AWS Artifact report naming DynamoDB in scope. artifact: security/amazon-dynamodb-trust-center.yml