AWSは Amazon Bedrock のデータセキュリティモデルとして、この語を公式ドキュメントで定義しています。逐語は「Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output.」——同じ段落の次の文でZDR(保存しない)を別のモデルとして説明している点が、このページの出発点です。1つの文で2つを並べている=別の約束だ、という一次情報上の根拠になります。
AWSは Bedrock について「Model providers don't have any access to those accounts. Because the model providers don't have access to those accounts, they don't have access to Amazon Bedrock logs or to customer prompts and completions.」と書いています。「クラウド事業者(運営者)」と「モデル提供元」は別の主体です。
“Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output. Also, Amazon Bedrock uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs.”— AWS 公式ドキュメント「Amazon Bedrock abuse detection」(2026-09-27 取得)
“Encryption and decryption operations that use a KMS key in an external key store are performed by your external key manager using your cryptographic key material, a feature known as hold your own keys (HYOKs).” “AWS KMS never interacts directly with your external key manager, and cannot create, view, manage, or delete your keys. Instead, AWS KMS interacts only with external key store proxy (XKS proxy) software that you provide.” “Your cryptographic key material never leaves your external key manager.”— AWS KMS 開発者ガイド「External key stores」(2026-10-01 取得)
BYOKの逐語(鍵素材を持ち込む)
“When you create a KMS key, by default, AWS KMS generates the key material for that KMS key. But you can create a KMS key without key material and then import your own key material into that KMS key, a feature often known as ‘bring your own key’ (BYOK).” “You can set an expiration time on import or call DeleteImportedKeyMaterial to revoke access immediately.”— AWS KMS 開発者ガイド「Importing key material」「Key stores」(2026-10-01 確認)
HYOKの逐語(Microsoft / Google Cloud)
“Keys are generated and stored in a single-tenant, FIPS 140-3 Level 3 HSM that only you control: Microsoft has no access to your key material, and you govern who can use each key.” “Microsoft can’t decrypt your key material or recover your HSM cluster without it.” “The security domain is protected by a quorum of RSA key pairs that you hold offline. Recovery requires your quorum, so no single person—and no Microsoft operator—can act alone.” “The external key never resides in or passes through Microsoft infrastructure; only your hardware uses it.”— Azure 公式ブログ「External key management for Azure Managed HSM」(2026-10-01 取得)
“Data encrypted using a Cloud EKM key can’t be decrypted without both the external key material and the internal key material.” “With Cloud EKM, you can use keys that you manage within a supported external key management partner to protect data within Google Cloud.”— Google Cloud ドキュメント「Cloud External Key Manager」(2026-10-01 取得)
⚠️ HYOKの引き換え条件: 鍵素材を外に置くということは、暗号演算のたびにあなたの側のシステムが応答する必要があるということです。自社HSMが落ちれば、クラウド側のサービスも復号できません。可用性・レイテンシ・運用責任(バックアップ、パッチ、障害対応)はあなた側に移ります。AWSのXKSでも「AWS KMS interacts only with external key store proxy (XKS proxy) software that you provide」と、プロキシの提供者・運用者が顧客側であることが明記されています。「最強の設定」ではなく「責任を引き受ける設定」です。
“In those rare circumstances where Microsoft requires such access, Customer Lockbox for Microsoft Azure provides an interface for your organization to review and approve or reject customer data access requests.” “The request remains in the customer queue for four days. After this time, the access request automatically expires and no access is granted to Microsoft engineers.” “Approve: The Microsoft engineer receives access for the duration specified in the request details …” “Deny: Customer Lockbox rejects the elevated access request by the Microsoft engineer and takes no further action.”— Microsoft Learn「Customer Lockbox for Microsoft Azure」(2026-10-01 取得)
“Access Approval lets you authorize requests from Google personnel to access Customer Data, Access Transparency helps you discover information about when Customer Data is accessed, and Key Access Justifications provides key access control for all interactions with at-rest Customer Data that is encrypted by a customer-managed key.” “Key Access Justifications lets you set a policy on Cloud KMS keys to view, approve, and deny key access requests depending on the provided justification code.” “Support tickets typically don’t require this access and our frontline support personnel don’t have this access.”— Google Cloud ドキュメント「Overview of Key Access Justifications」「View and act on justifications」(2026-10-01 取得)
“Safety review must not create a new way for OpenAI personnel to read protected customer content. Encrypted customer content is decrypted in an approved, hardware-attested safety runtime that disables human access. Only bounded safety signals and operational metadata leave the PSP protected review in plaintext.” “The Safety Review Runtime, a hardware-attested computing environment that disables human access, is designed to be the only workload that can decrypt customer content.”— OpenAI 開発者ドキュメント「ZDR with Private Safety Processing」(2026-10-01 取得)
“By default, no Anthropic personnel can read your retained conversations. Human review can occur only through a controlled access path … when content is flagged by our automated trust and safety systems”— Anthropic サポート「Data retention practices for covered models」(2026-09-27 取得)
“This mode allows your inputs and outputs to be retained for human review by AWS. Review is carried out by AWS within the AWS boundary — the model provider does not review your content”— AWS 公式ドキュメント「Amazon Bedrock data retention」(aws_review モードの説明・2026-09-27 取得)
⚠️ 「承認フローがある=必ず承認が要る」ではありません。Microsoft は Customer Lockbox が発動しない例として、逐語で「Emergency scenarios that fall outside of standard operating procedures and require urgent action from Microsoft to restore access to online services or to prevent corruption or loss of customer data, or to investigate a security or abuse incident. … These “break glass” events are rare …」と書いています。ZOAは「絶対に人が入れない」ではなく「通常運用では人が入れない+例外の条件が明示されている」と理解するのが正確です。例外の条件そのものが公開されている点に、確認する価値があります。
鍵を誰が持っているか次第です。CMKでも鍵素材は提供者のKMS内にあり、復号を実行するのは提供者側の基盤です。「提供者の人間が復号できない」ことの保証にはなりません。HYOKまで進めて初めて「鍵素材が提供者の外に出ない」と言えます(AWSの逐語:「Your cryptographic key material never leaves your external key manager.」)。
Azureの公式表現は条件付きです。逐語で「When Azure confidential computing is enabled and properly configured, Microsoft can’t access unencrypted customer data.」——有効化して正しく構成した場合という条件が明記されています。既定でそうなるわけではなく、設定の確認が必要です。なお、AzureのConfidential VM FAQには「Azure doesn’t have operating procedures for granting confidential VM access to its employees, even if a customer authorizes the access.」という記載もあります。