AWS + Bedrock, the validated path
Amazon Bedrock on your own credentials; IAM-scoped workers in private subnets with no general egress.
Read the reference
Use cases
Each path ends in something you can hand a control owner. Pick the one closest to your first audit question.
8 use cases · 4 available today
Amazon Bedrock on your own credentials; IAM-scoped workers in private subnets with no general egress.
Read the reference
One install command adds recording hooks; every session emits signed, schema-versioned activity events.
Install the hooks
Unattended agents pause for portal approval; if the portal is unreachable, the action is denied.
Wire approvals
Narratives for SR 11-7, FFIEC, DORA (EU operational resilience), EU AI Act, ISO 42001, and SOC 2, backed by records your engineers already produce.
See the control mappings
In the pull request itself: which sessions produced the change, what was approved, whether rationale is on record.
Read the provenance docs
Hash-bound JSON or zip packages a local verifier checks offline — no raw prompts or source inside.
Read the provenance docs
OS-enforced file, network, and process boundaries for MCP servers, under the same governance rules.
See the pattern
A scripted pass in your account: ingest, approvals, Agent Run Audit, PR evidence, worker dispatch, audit-chain verification.
Talk to us about scope
Don’t see your workflow?
Start with the AWS walkthrough; we’ll map your control owners onto the same evidence pack.
Request a demo