“DeepSeek” refers to two different things: The DeepSeek AI models are software (large language models) that generate responses to your prompts. These AI models were built by Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd. (the “DeepSeek company”), based in China.
Bells Up AI runs the DeepSeek AI models on Amazon’s servers in the United States. The DeepSeek company itself never receives your prompts, your documents, or the models’ responses.
Your data stays on Amazon’s infrastructure — the DeepSeek company has zero access. However, model safety concerns and US government restrictions persist regardless of hosting.
| Question | Answer |
|---|---|
| Can the DeepSeek company access your prompts or documents? | No — the DeepSeek company never receives them |
| Can the DeepSeek company train AI on your prompts or documents? | No — the DeepSeek company has zero access |
| Does your data reach servers in China? | No — data stays within AWS US infrastructure |
| Does China's National Intelligence Law apply to your prompts? | No — the DeepSeek company never possesses your data (details) |
| Does Amazon Bedrock store your prompts or documents? | No — Amazon Bedrock applies zero data retention by default (not stored) |
| Does Amazon train AI on your data? | No — prohibited by contract |
| Does Amazon scan your data for abuse? | Yes — but automated; AWS states no operators of the service can access your inputs or outputs (zero operator access) (details) |
| Can Amazon employees or contractors review your prompts or responses? | No — AWS Bedrock uses a zero operator access (ZOA) data security model; content flagged as apparent CSAM may be reviewed for confirmation and reporting. Access to data stored on Amazon’s infrastructure is separately limited (details) |
| Known security concerns about DeepSeek? | Yes — documented concerns (details) |
| Model safety evaluation results | Below US reference models (details) |
| US government restrictions on DeepSeek? | Yes — federal law and state bans (details) |
| Is this disclosure legal advice? | No. Bells Up AI does not provide legal advice. Attorneys should exercise independent professional judgment regarding model selection. |
Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Amazon Web Services — the cloud provider that runs the model and where your prompts are processed — holds SOC 2 and ISO 27001 certifications.
Bells Up AI believes that our customers should have access to the full range of AI tools and the information they need to make informed professional decisions about which models to use, and when and how to use them. Model selection is always the attorney’s professional judgment call.
Federal law restricts the use of DeepSeek for certain users. The FY 2026 NDAA (P.L. 119-60) prohibits parts of the US federal government from using AI “developed by” DeepSeek. Attorneys performing work for the Department of Defense, the Intelligence Community, or their contractors may wish to consider whether this restriction applies to their work. Additionally, at least 17 states have banned DeepSeek on government devices. As of the date of this disclosure, no US jurisdiction has banned the use of DeepSeek for private or commercial use. See the full regulatory landscape.
DeepSeek has been the subject of significant privacy and security scrutiny from government agencies, cybersecurity firms, and policy organizations. Security researchers have documented exposed databases containing user chat logs, disabled encryption in DeepSeek’s mobile applications, and code linking to Chinese state-owned telecommunications infrastructure. Government investigations are ongoing in multiple countries. See Concerns About DeepSeek and Data Privacy for the full analysis.
Some of these privacy concerns do not apply to the use of DeepSeek through Bells Up AI, because Bells Up AI accesses DeepSeek models through Amazon. Pursuant to this contractual relationship between Bells Up AI and Amazon, and the contracts between Amazon and DeepSeek, the prompts and documents submitted by Bells Up AI users, and the model’s responses, remain on Amazon’s servers. DeepSeek (the company) has no access to the Amazon infrastructure that runs the DeepSeek models used to respond to your prompts. When we send your encrypted communications to Amazon for using DeepSeek models, your data stays within the United States. Thus, we are using different infrastructure than the servers involved in the documented privacy and security incidents involving DeepSeek’s own applications and servers.
Nevertheless, model behavior and safety risks persist regardless of where the model is hosted. Evaluations regarding model safety apply regardless where the model runs. Evaluations by NIST’s Center for AI Standards and Innovation, by Cisco, and by the vendor Enkrypt AI found that DeepSeek models have significantly higher jailbreak success rates, greater susceptibility to following malicious instructions, and elevated harmful content generation compared to US reference models. NIST found that DeepSeek models echoed four times as many inaccurate and misleading Chinese Communist Party narratives as US reference models. See What Bedrock Changes — and What It Does Not for the full analysis.
Practice considerations. DeepSeek may be appropriate for non-privileged legal research on public information, general knowledge questions unrelated to client matters, internal non-client administrative work, and comparing model outputs for evaluation purposes. DeepSeek does not receive your prompts, documents, or responses when you use the model through Bedrock, and Amazon does not train on them. The documented safety failures and alignment concerns affect output reliability. Use heightened caution whenever you would rely on the model’s output or when opposing counsel or a court might examine the AI tools used. Counsel’s use of a model with extensive government bans and documented safety failures could raise additional questions.
When you use DeepSeek AI models through Bells Up AI, three parties are involved in processing your request:
Each party operates under different obligations and constraints. This disclosure explains what each party can and cannot do with your data, the documented concerns about DeepSeek, how Amazon Bedrock’s architecture addresses those concerns, and what remains unaddressed. We cite governing contracts, published research, and enacted legislation throughout.
What DeepSeek Does: DeepSeek develops and trains AI models. DeepSeek provides the trained model weights to Amazon for deployment on Amazon’s infrastructure. DeepSeek’s models are “open-weight,” meaning the model files are publicly available for inspection and deployment.
DeepSeek cannot access your prompts, documents, or the model’s responses. This is a technical restriction. DeepSeek has no access to the Amazon infrastructure where its models are deployed (per AWS documentation).
In order to run AI models like the DeepSeek models you access through Bells Up AI, Amazon maintains “Model Deployment Accounts”, which model developers like DeepSeek do not have access to:
“Model providers don’t have any access to those accounts. After delivery of a model from a model provider to [Amazon], Amazon Bedrock will perform a deep copy of a model provider’s inference and training software into those accounts for deployment. Because the model providers don’t have access to those accounts, they don’t have access to Amazon Bedrock logs or to customer prompts and completions.”
DeepSeek cannot train models on your data because DeepSeek never receives your data. This protection is architectural — it does not depend on DeepSeek’s policies, promises, or privacy practices.
If you were to use DeepSeek’s own website or mobile applications directly, your data would be stored on DeepSeek’s servers in China, subject to Chinese law, and governed by DeepSeek’s privacy policy. Through Bells Up AI, none of that applies. Your data never reaches DeepSeek.
DeepSeek has been the subject of significant privacy and security scrutiny from government agencies, cybersecurity firms, and policy organizations. This section summarizes the documented concerns. These concerns are relevant context for attorneys making decisions about AI tool selection, even though the Bedrock architecture prevents most of the identified data privacy risks from affecting your use through Bells Up AI.
DeepSeek was founded in July 2023 by Liang Wenfeng, who holds 84% ownership. DeepSeek is an affiliate of High-Flyer (Huanfang Quantitative), a Hangzhou-based hedge fund also founded by Liang. High-Flyer received a “National High-Tech Enterprise” designation from the Chinese government in December 2023, securing tax breaks and government-backed funding for AI research and development.
Exiger, a supply chain risk analytics firm, found that DeepSeek researchers have worked on 396 AI research projects funded by the People’s Liberation Army (PLA) and had affiliations with 42 Chinese government talent recruitment programs. A senior U.S. State Department official stated that DeepSeek “has willingly provided and will likely continue to provide support to China’s military and intelligence operations,” citing its appearance in more than 150 PLA procurement records.
Article 7 of China’s National Intelligence Law (2017, amended 2018) states: “All organizations and citizens shall support, assist, and cooperate with national intelligence efforts in accordance with law.” Under this and related Chinese laws (the Data Security Law and the Personal Information Protection Law), data stored on Chinese servers can be subject to compelled disclosure to Chinese intelligence services, and Chinese companies cannot provide data to foreign courts or governments without Chinese government approval.
The practical scope of Article 7 is debated among legal scholars. The U.S. Department of Homeland Security has stated that Chinese companies “can be directed to covertly install backdoors” into equipment or software under these laws.
The following incidents involved DeepSeek’s own applications and servers — not the model weights hosted on Bedrock. They are relevant as indicators of the company’s security practices.
Wiz Research Database Exposure (January 2025):
Cybersecurity firm Wiz Research discovered a publicly accessible database belonging to DeepSeek that required no authentication and contained over 1 million log entries, including plaintext user chat histories, API secret keys, and backend operational details. DeepSeek secured the database the same day it was reported.
NowSecure iOS App Findings (February 2025):
NowSecure’s security analysis of DeepSeek’s iOS mobile app found that the app disabled Apple’s App Transport Security (sending data over unencrypted channels), used deprecated encryption with a hard-coded key, stored credentials insecurely on-device, and transmitted user data to servers controlled by ByteDance. NowSecure recommended organizations remove the DeepSeek iOS app from their environments.
Feroot Security — China Mobile Code (February 2025):
Feroot Security discovered obfuscated code embedded in DeepSeek’s web login page that, when deciphered, revealed links to China Mobile’s infrastructure. China Mobile was banned from operating in the U.S. by the FCC in 2019 due to national security concerns. Independent experts consulted by the Associated Press confirmed the code’s presence, though no actual data transfer to China Mobile was observed during testing.
In April 2025, the House Select Committee on the CCP released a report titled “DeepSeek Unmasked.” The Committee found that DeepSeek covertly funnels American user data to the CCP, that 85% of chatbot responses on sensitive topics were manipulated to align with CCP narratives, and that DeepSeek was trained using over 60,000 Nvidia chips potentially obtained in circumvention of U.S. export controls.
When you use DeepSeek through Bells Up AI, you are using DeepSeek’s model weights running on Amazon’s infrastructure. This changes the risk profile in specific, documentable ways.
Amazon Bedrock’s architecture eliminates several categories of risk identified in the section above:
Bedrock changes where the model runs. It does not change how the model behaves. The following concerns persist regardless of hosting infrastructure:
Model Safety:
In May 2026, NIST’s Center for AI Standards and Innovation (CAISI) published a capability evaluation of DeepSeek V4 Pro — a newer DeepSeek model that is not offered through Bells Up AI — finding its capabilities lag the U.S. frontier by roughly eight months.
CCP Narrative Alignment:
According to NIST, DeepSeek models echoed four times as many inaccurate and misleading CCP narratives as U.S. reference models. The House Select Committee found 85% of responses on sensitive topics (democracy, Taiwan, Hong Kong, human rights) were manipulated to align with CCP positions. These biases are embedded in the model weights and will produce the same outputs on any hosting infrastructure.
Model Weight Supply Chain:
DeepSeek developed the model weights that run on Bedrock. DeepSeek’s models are open-weight, allowing researchers to inspect them. However, no public evidence exists that AWS performs independent security review or audit of model weights beyond standard software security scanning. The question of whether model weights could contain undisclosed capabilities is an active area of AI security research.
Reputational Considerations:
The distinction between “using DeepSeek directly” and “using DeepSeek’s model on Amazon’s servers” is technically meaningful but may not satisfy all audiences. Fox Rothschild LLP has banned its lawyers from using DeepSeek tools entirely. Attorneys should consider how their AI tool selection may be perceived by clients, opposing counsel, and courts.
DeepSeek is subject to federal, state, and international government restrictions. These restrictions are relevant for all attorneys, and especially for those with government clients, security clearances, or government contractor clients.
The FY 2026 NDAA (P.L. 119-60), signed into law on December 18, 2025, contains two provisions directly targeting DeepSeek:
The ban language is origin-based.
Section 1532 prohibits AI “developed by” DeepSeek, High Flyer, or associated entities. This language targets the origin of the AI, not the hosting infrastructure. The DeepSeek model weights running on Bedrock were developed by DeepSeek. Legal analyses from Crowell & Moring, WilmerHale, and King & Spalding all describe the prohibition as applying to AI “developed by” the named entities, without any carve-out for third-party hosting. Bedrock hosting likely does not create an exception to the NDAA ban for covered entities.
AWS itself publishes documentation on implementing Service Control Policies to block DeepSeek models across an AWS Organization, for organizations that need to restrict access to DeepSeek models even on Bedrock.
Multiple federal agencies have independently banned DeepSeek, including the U.S. Navy, NASA, and the Department of Commerce. In December 2025, bipartisan congressional leaders formally requested the Pentagon add DeepSeek to the Section 1260H list of Chinese military companies. DeepSeek was not added to the June 8, 2026 Section 1260H update, despite that request.
At least 17 U.S. states have banned DeepSeek on government devices and networks, including Texas, New York, Virginia, and Pennsylvania. As of the date of this disclosure, no U.S. jurisdiction has banned private or commercial use of DeepSeek.
Italy became the first country to block DeepSeek (January 30, 2025) under GDPR after DeepSeek reportedly told Italian data protection authorities it would not cooperate with their information request. Australia, South Korea, and Taiwan have banned DeepSeek on government devices. Data protection authorities in Italy, Ireland, Belgium, the Netherlands, and France have launched formal investigations into DeepSeek’s GDPR compliance.
No federal executive restriction on cloud-provider access to DeepSeek models has been enacted. In June 2026, the administration declined an interagency recommendation to add DeepSeek to the Commerce Department’s Entity List. The bipartisan “No DeepSeek on Government Devices Act” (H.R. 1121 / S. 765) has been introduced in both chambers of Congress. A separate bill, the Deterring American AI Model Theft Act (H.R. 8283), was introduced and referred to committee (April 2026); it is an export-control measure aimed at preventing foreign model theft, would not restrict U.S. commercial use, and has not become law. On April 23, 2026, the White House Office of Science and Technology Policy issued a memorandum (“Adversarial Distillation of American AI Models,” NSTM-4) accusing Chinese AI labs — DeepSeek among them — of running industrial-scale campaigns to copy U.S. frontier models through “distillation.” The memorandum directs federal agencies to coordinate defenses with U.S. AI developers; it does not itself restrict private use of DeepSeek, but it reflects continued federal scrutiny of the company. In April 2026, the House Select Committee on the CCP and the House Committee on Homeland Security opened a joint inquiry into U.S. companies’ use of PRC open-weight AI models, expanded in July 2026, and have sent information requests to companies including Airbnb, Anysphere, and DoorDash. This inquiry is separate from the Select Committee’s April 2025 “DeepSeek Unmasked” report described above, which examined DeepSeek itself. The 2026 inquiry concerns how U.S. companies deploy open-weight models; it imposes no restriction on private or commercial use, and none has resulted from it as of this review. Bells Up AI monitors these developments as part of our ongoing vendor assessment.
September 2026 federal advisory. On September 8, 2026, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation issued a joint cybersecurity advisory, AA26-251A, titled “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies.” The advisory names six China-based AI companies — DeepSeek, Moonshot AI, Alibaba, Z.AI, MiniMax, and StepFun — that it states extracted training data from U.S. frontier models. It states that between late 2024 and mid-2025, DeepSeek “distilled specialized training data and capabilities from” U.S. frontier models, including Claude, Gemini, GPT, and Grok variants, “to train their R1 and V3 models.” The advisory directs its recommendations to U.S. AI developers, on detecting and responding to distillation. It imposes no restriction, obligation, or requirement on companies or individuals that use these models. It concerns how these models were trained, not how your prompts and responses are handled when you use them; the data-handling protections described in this disclosure are unaffected.
Amazon provides two distinct services relevant to how your data is handled:
What Amazon Bedrock Does: Amazon Bedrock is the service that hosts and runs the DeepSeek AI models. When you submit a prompt, Bells Up AI sends it to Amazon Bedrock, which processes it through DeepSeek model weights running on AWS-owned compute and returns the response.
Amazon Bedrock’s Core Commitments:
No Storage of Your Prompts or Responses:
“Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output. Also, Amazon Bedrock uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs.”
No Training on Your Data:
Amazon does not use your prompts and responses to train its own models, and does not share them with the model provider. AWS states that retained inputs and outputs (for the limited set of models that require retention) are “stored and processed by AWS and are not shared with third-party model providers,” per the Amazon Bedrock Abuse Detection Documentation.
Data Stays in the United States: DeepSeek V3.2 is processed in the us-east-1 (Northern Virginia) region. DeepSeek-R1 is accessed through a US cross-region inference profile and may be processed in us-east-1, us-east-2 (Ohio), or us-west-2 (Oregon), as AWS selects for capacity. In all cases, your data is not routed outside the United States; data stored at rest remains in the source region.
The optional “Improve my prompt” tool sends the draft prompt to Amazon Bedrock’s prompt-optimization service. The tool sends your draft prompt to Amazon Bedrock regardless of the model you select. Conversations, documents, and workflow runs are processed by the model you selected.
Amazon Bedrock runs automated content scanning on data processed through the service. If that scanning flags apparent child sexual abuse material, the AWS Service Terms provide:
“If we detect apparent child sexual abuse material (“CSAM”), you agree and instruct that we may: (a) review the flagged input or output to determine if it is CSAM, and (b) report the incident to the National Center for Missing and Exploited Children or other authority.”
The Service Terms also provide that, for certain models identified on Amazon’s Bedrock abuse-detection documentation, Amazon Bedrock stores inputs and outputs for up to 30 days to detect terms-of-service violations and may review them if a potential violation is detected. None of the models available through Bells Up AI are identified on that list as of this review.
Apart from these provisions, Amazon’s abuse-detection documentation describes a zero operator access model:
“Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output.”
What this means:
This automated scanning is narrower in scope than the abuse monitoring systems used by direct API providers like OpenAI or Google, which retain data for up to 30 or 55 days and may involve human review of flagged content. Amazon Bedrock’s abuse detection operates at the infrastructure level and does not involve the model provider (DeepSeek).
While DeepSeek never receives the content of your prompts or responses, Amazon may share non-content usage information with third-party model providers:
“We may share information, that does not include Your Content, about your use of a third-party model with the provider of that third-party model.”
This metadata may include identifiers such as Bells Up AI’s AWS Account ID, the AWS region, the model used, request counts, token usage, and timestamps. It contains no content from your prompts, documents, or responses.
What This Means: Separately from Amazon Bedrock, the Bells Up AI application itself runs on Amazon’s cloud infrastructure. This includes:
Can Amazon Access This Data?
Amazon operates the physical servers and storage infrastructure we use. Amazon’s access to data stored on its infrastructure is governed by contract and verified by independent audits, which test whether Amazon’s actual practices match its contractual commitments:
“AWS will not access or use, or disclose to any third party, any Customer Data, except, in each case, as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body (such as a subpoena or court order).”
This prohibits Amazon from using your data to develop Amazon’s own AI or other products, or from providing your data to others for such purposes.
Amazon’s SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.
Technical Protections:
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all communications |
| Encryption at rest | AES-256 for all stored data |
| Server storage | Encrypted at the hardware level |
| Access controls | Credentials managed through Amazon’s identity system; no hardcoded passwords |
Bells Up AI’s use of Amazon services is governed by:
DeepSeek models on Bedrock are sold by AWS under MIT open-source licenses. The data handling protections described in this disclosure flow from AWS’s platform-level contractual commitments and architectural controls, rather than from any DeepSeek-specific contractual terms with AWS customers. The protection is architectural and AWS-contractual.
Under the Data Processing Addendum, Amazon acts as a “data processor” — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.
Amazon Bedrock and the underlying infrastructure maintain the following certifications:
We encourage you to review the source documents:
| Document | What It Covers | Link |
|---|---|---|
| Amazon Bedrock Data Protection | No-storage, no-training, model provider isolation | View |
| Serverless Third-Party Models Terms | Terms governing DeepSeek models on Bedrock | View |
| Amazon Web Services Data Processing Addendum | Amazon’s role as processor, access limitations | View |
| Amazon Bedrock Security & Compliance | Certifications (SOC, ISO, HIPAA) | View |
| FY 2026 NDAA (P.L. 119-60) | Federal ban on DeepSeek for DoD and IC | View |
| NIST CAISI DeepSeek Evaluation | Safety and security evaluation results | View |
| NIST CAISI DeepSeek V4 Pro Evaluation | Capability evaluation of a newer, non-offered DeepSeek model | View |
| House Select Committee Report | Congressional investigation findings | View |
| DeepSeek Privacy Policy | DeepSeek’s own data handling (does not apply via Bedrock) | View |
If you have questions about how your data is protected when using DeepSeek models through Bells Up AI, or about whether DeepSeek models are appropriate for your specific use case, contact us at info@bellsup.ai.
This document describes data handling for DeepSeek models accessed via Amazon Bedrock. Other models available through Bells Up AI have different data flows and risk profiles — see the privacy information page for each model family.
This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.
The regulatory and policy landscape for DeepSeek is evolving rapidly. Bells Up AI reviews this disclosure periodically, but attorneys should independently verify current regulatory requirements. The “Last Reviewed” date above reflects when this document was last updated.