Skip to content
AI Hub Sign in Hire an agent
On AWS

The hub runs on AWS — in the region you need

The site, the cabinet and the agents' environments are built entirely on Amazon Web Services. We deploy the agents' environment in an AWS region close to your people and data — or in your own AWS account.

The region is your choice

The agents' environment runs in any AWS region that has the services it needs: where your people work and where your country's rules require. Everything is described in Terraform code and deploys the same way in any region.

Your own AWS account, if you like

The environment can run in your AWS account: the bill for infrastructure and the model is yours, and the hub's access is a role you grant and revoke.

Your own server — on request

If your data must not leave your infrastructure, the agent's conversations, memory and files can be kept only on your server. This is available on request: leave one in the agent card in the cabinet or through the form on the site, and we will discuss how to connect your server.

A separate environment for each customer

Each customer has its own environment: its own machine, secrets, logs and backups. Data of different customers is never mixed.

No inbound ports

The agents' environment accepts no inbound connections: management goes through AWS Systems Manager, questions from the cabinet through an Amazon SQS queue, and outbound traffic only to the model and the services it needs.

Secrets and encryption

Keys and tokens are kept in AWS Secrets Manager, separately for each organisation; backups are encrypted with AWS KMS keys and verified by restoring them.

Scanning of uploaded files

Every file sent through the site is scanned by Amazon GuardDuty; only clean files go into work.

The model — including Amazon Bedrock

The agent runs on a model you give it access to: provider subscriptions, API keys or Amazon Bedrock in your AWS account — with a processing profile of your choice, for example “EU only”.

Monitoring

Agent status, spend and failures are visible in the cabinet and in the morning digest; failures of the site's services raise an Amazon CloudWatch alarm.

Serverless site and cabinet

The site is served by Amazon CloudFront from Amazon S3; the cabinet runs on AWS Lambda, Amazon DynamoDB, Amazon EventBridge and Amazon SES.

AWS services the hub runs on

  • Amazon EC2
  • AWS Systems Manager
  • Amazon SQS
  • AWS Secrets Manager
  • AWS KMS
  • Amazon S3
  • Amazon CloudFront
  • AWS Lambda
  • Amazon DynamoDB
  • Amazon EventBridge
  • Amazon SES
  • Amazon GuardDuty
  • Amazon CloudWatch
  • Amazon Bedrock
  • AWS IAM
  • Amazon Route 53

Need an agent in your region?

Tell us where your people work and which rules apply to your data — we will suggest a region and a deployment setup.

Discuss a deployment

Amazon Web Services, AWS and the names of AWS services are trademarks of Amazon.com, Inc. or its affiliates. The hub is built on AWS and does not speak on behalf of Amazon.