Skip to content

AWS Customer Guide: Detecting and responding to image-based sexual abuse (IBSA)

5 minute read
Content level: Foundational
0

If you build or operate a service on AWS where users can share, generate, process, distribute, or store imagery, you might encounter non-consensual intimate imagery (NCII) or other forms of image-based sexual abuse (IBSA).

This guide covers how image-based sexual abuse (IBSA) relates to the AWS Acceptable Use Policy (AUP), and detection and operational tools that you can integrate with directly. It also covers how to refer affected End Users to specialist support, and report NCII and IBSA content that’s hosted on AWS.

What is IBSA?

IBSA refers to sexually explicit photos or videos of an identifiable adult that’s shared online without consent, including content that’s created or altered using AI or other digital tools. It’s also known as non-consensual intimate images (NCII), non-consensual sexual intimate images (NCSII), or "revenge porn." It’s a serious harm. For the people depicted, non-consensual sharing of intimate images can cause lasting distress, and the content can quickly spread across platforms and services after it appears.

Note: To learn more about Amazon's commitment and the resources that are available to combat online child sexual exploitation and abuse (CSEA), see AWS Customer Guide: Leveraging global child safety partnerships for CSEA prevention.

How the AWS Acceptable Use Policy (AUP) applies to IBSA

Using AWS services to create, distribute, or otherwise make available IBSA is prohibited under the AWS AUP. As an AWS customer, you agree to the AUP. Under the AWS Customer Agreement, you're responsible for your own content and the content that your End Users place on the services that you operate.

As the operator of your service, you have the most access and control to detect IBSA, act on reports, and remove violating content. If you don't appropriately address prohibited content, then AWS might take action in accordance with your AWS Customer Agreement and AWS AUP. If you or an abuse reporter disagrees with any action that AWS takes, then AWS Trust & Safety can engage with the relevant parties to discuss the action.

Customer resources

The rest of this guide provides third-party resources, including detection tools, end-user support routes, and reporting processes that can help you take action.

Detection tool: StopNCII.org

StopNCII.org is a hash-matching online tool operated by the UK-based Revenge Porn Helpline, part of the not-for-profit charity South West Grid for Learning (SWGfL). Anyone over the age of 18 concerned about their own intimate images or videos being shared without consent can generate a digital fingerprint, called a hash, of their content through their own device—the original content never leaves the user’s device and is not shared with any service. StopNCII.org shares those hashes with participating companies, which uses them to detect and block matching content that tries to be uploaded to their services. If you operate a service that wants to prevent the spread of non-consensual intimate imagery, you can apply directly to StopNCII.org to participate.

Operational tool: STISA

Survivors & Tech Solving Image-Based Sexual Abuse (STISA) works for survivors of image based sexual abuse by equipping hotlines and helplines with resources to stop their revictimization. STISA coordinates across jurisdictions to support consistent IBSA reporting and permanent removal process. As hotlines and helplines adopt state-of-the art solutions to support survivors, if you operate a service that receives IBSA reports, you may benefit by proactively querying against verified IBSA content, curated by STISA, which will bring greater consistency in removal.

Referring affected end users to specialist support

If you operate a user-facing service, then you might want to refer End Users that are affected by IBSA to specialist support in their jurisdiction within your own reporting and moderation flows. Many survivor-support hotlines and statutory bodies offer confidential support, including help with locating where content is hosted across the internet, coordinating removal across multiple platforms, and accessing trauma-informed support. AWS doesn’t maintain a directory of these organizations or endorse any individual service. To identify the appropriate organization in each jurisdiction that you serve, you can do a standard search or consult your own legal team or trust and safety teams.

Contact AWS

If you’re looking to strengthen IBSA detection and response capabilities on your platform, then reach out to your AWS account team.

Note: If you identified IBSA content that you believe is hosted on AWS services, then directly contact the website or service that's hosting the content. If you can't identify the host, or you contacted the host and they haven’t responded or removed the content, then you can submit a report to AWS Trust & Safety. For instructions, including the information that AWS requires and what AWS does with your report, see How do I report abuse of AWS resources?

Related resources

Note: This article is provided for informational purposes only and does not constitute legal advice. Information listed in this article was last updated July 2026.