Loading image...Kiro

Product

  • About Kiro
  • Agents
  • IDE
  • CLI
  • Web
  • Mobile
  • Crew
  • Pricing
  • Downloads

For

  • Enterprise
  • Startups
  • Students

Community

  • Overview
  • Ambassadors
  • Case studies
  • Discord
  • Events
  • Powers
  • Shop
  • Showcase

Resources

  • Docs
  • Blog
  • Changelog
  • FAQs
  • Report a bug
  • Suggest an idea
  • Billing support

Social

Site TermsLicenseResponsible AI PolicyLegalPrivacy PolicyCookie Preferences
Loading image...Kiro
  • Agents
  • Enterprise
  • Pricing
  • Docs
SIGN INDOWNLOADS
Loading image...Kiro

Get Started

InstallationAuthenticationYour first project

Models

OverviewAvailable modelsReasoning effortAWS GovCloud (US) models

Features

How Kiro worksACP integrations
Specs
Steering
Hooks
MCP
Permissions
Custom agents
Workflows
Agent Skills
Powers
Cloud sessionsCompactionKiroignoreCheckpoints and rewind
Built-in tools
Configuration scopes

IDE 1.x

What's new in 1.0
Setup & First Run
Editor
Chat
Experimental
Troubleshooting0.x reference

CLI

What's new in V3
Setup & First Run
Terminal UI
Chat
Fullscreen modeVoice modeHeadless modeACPAuto complete
Experimental
2.x reference

Crew

Quick startInstallationRunning 24/7
Chat
Agent Capabilities
Features
Interfaces
Apps
System & storageConfigurationSecurityTroubleshooting

Web

Setup & First RunIdentity Center
Connect your repositories
Working with the agent
Autonomous modeAutomationsMemoryConfiguration Sync
Sandbox

Mobile - Preview

Overview

Commands and Reference

CLI commandsSlash commandsBuilt-in toolsExit codesSettings

Billing

OverviewManaging your subscriptionUpgrading your planDowngrading your planCancelling your planPurchasing add-on creditsManaging your paymentsManaging usage notificationsManaging your taxesContacting billing supportDeleting your accountRelated questions

Enterprise

ConceptsOnboarding quickstart
Connecting your identity provider
Deployment optionsSubscribe your teamManage subscriptions
Governance
Monitor and track
SettingsManaged updatesBillingIAMSupported regions

Privacy and Security

OverviewData protectionCode referencesCompliance validationInfrastructure securityIAM permissionsFirewalls, proxies, and data perimetersVPC endpoints (AWS PrivateLink)

Guides

Overview
Language support
Learn by playing

Migration

Migrating from Q DeveloperMigrating from VSCodeUpgrading from Q CLI
  1. Docs
  2. Privacy and Security
  3. Compliance validation
View as Markdown

Compliance validation for Kiro

View as Markdown

Kiro participates in the following compliance programs.

  • HIPAA: Kiro IDE and CLI are HIPAA eligible. HIPAA eligibility means Kiro can be used as part of a HIPAA-compliant architecture. Your organization remains responsible for configuring its use of Kiro to meet HIPAA requirements.
  • ISO/IEC 27001:2022: Kiro is included in the defined scope of AWS's ISO/IEC 27001:2022 certification. The certification is independently verified by EY CertifyPoint, an ISO certification body accredited by the Dutch Accreditation Council.

Review the public AWS ISO/IEC 27001:2022 certificate and the current AWS services-in-scope listing for certification and coverage details.

For additional evidence that can support a security, procurement, or vendor-risk review, download available reports through AWS Artifact. For instructions, see Downloading reports in AWS Artifact. See Data protection for details about how Kiro stores, processes, and encrypts customer data.

Info

If you sign in to Kiro with GitHub or Google, you cannot download third-party audit reports using AWS Artifact. You must sign in with AWS Builder ID or AWS IAM Identity Center to access Artifact.

Your compliance responsibility when using AWS services is determined by the sensitivity of your data, your company's compliance objectives, and applicable laws and regulations. AWS provides the following resources to help with compliance:

  • Security Compliance & Governance – Solution implementation guides that discuss architectural considerations and provide steps for deploying security and compliance features.
  • HIPAA Eligible Services Reference – Lists HIPAA eligible services. Not all AWS services are HIPAA eligible.
  • AWS Compliance Resources – Workbooks and guides that might apply to your industry and location.
  • AWS Customer Compliance Guides – Summarize best practices for securing AWS services and map guidance to security controls across multiple frameworks including NIST, PCI, and ISO.
  • Evaluating Resources with Rules – AWS Config assesses how well your resource configurations comply with internal practices, industry guidelines, and regulations.
  • AWS Security Hub – Provides a comprehensive view of your security state within AWS and checks compliance against security industry standards and best practices.
  • Amazon GuardDuty – Detects potential threats to your AWS accounts, workloads, containers, and data by monitoring your environment for suspicious and malicious activities.
  • AWS Audit Manager – Helps you continuously audit your AWS usage to simplify how you manage risk and compliance with regulations and industry standards.
Page updated: September 3, 2026
Code references
Infrastructure security