Amazon API Gateway
Developer Guide

API Gateway Compliance

For information about API Gateway compliance with various security compliance regulations and audits standards, see the following pages:

In addition, see the following for details about how API Gateway is compliant with the PCI DSS and HIPAA standards.


API Gateway supports the processing, storage, and transmission of credit card data by a merchant or service provider, and has been validated as being compliant with Payment Card Industry (PCI) Data Security Standard (DSS). For more information about PCI DSS, including how to request a copy of the AWS PCI Compliance Package, see PCI DSS Level 1.


This is a HIPAA Eligible Service. For more information about AWS, U.S. Health Insurance Portability and Accountability Act of 1996 (HIPAA), and using AWS services to process, store, and transmit protected health information (PHI), see HIPAA Overview.

On this page: