The region is your choice
The agents' environment runs in any AWS region that has the services it needs: where your people work and where your country's rules require. Everything is described in Terraform code and deploys the same way in any region.
The site, the cabinet and the agents' environments are built entirely on Amazon Web Services. We deploy the agents' environment in an AWS region close to your people and data — or in your own AWS account.
The agents' environment runs in any AWS region that has the services it needs: where your people work and where your country's rules require. Everything is described in Terraform code and deploys the same way in any region.
The environment can run in your AWS account: the bill for infrastructure and the model is yours, and the hub's access is a role you grant and revoke.
If your data must not leave your infrastructure, the agent's conversations, memory and files can be kept only on your server. This is available on request: leave one in the agent card in the cabinet or through the form on the site, and we will discuss how to connect your server.
Each customer has its own environment: its own machine, secrets, logs and backups. Data of different customers is never mixed.
The agents' environment accepts no inbound connections: management goes through AWS Systems Manager, questions from the cabinet through an Amazon SQS queue, and outbound traffic only to the model and the services it needs.
Keys and tokens are kept in AWS Secrets Manager, separately for each organisation; backups are encrypted with AWS KMS keys and verified by restoring them.
Every file sent through the site is scanned by Amazon GuardDuty; only clean files go into work.
The agent runs on a model you give it access to: provider subscriptions, API keys or Amazon Bedrock in your AWS account — with a processing profile of your choice, for example “EU only”.
Agent status, spend and failures are visible in the cabinet and in the morning digest; failures of the site's services raise an Amazon CloudWatch alarm.
The site is served by Amazon CloudFront from Amazon S3; the cabinet runs on AWS Lambda, Amazon DynamoDB, Amazon EventBridge and Amazon SES.
Tell us where your people work and which rules apply to your data — we will suggest a region and a deployment setup.
Amazon Web Services, AWS and the names of AWS services are trademarks of Amazon.com, Inc. or its affiliates. The hub is built on AWS and does not speak on behalf of Amazon.