AWS AI technology
Built on AWS, secured by design
Perixope builds on Amazon Bedrock and the AWS services your teams already use, with security and control designed in from the first day.
The AWS AI technology stack
AI
- Amazon Bedrock
- Amazon Nova
- Bedrock Knowledge Bases
- Bedrock Guardrails
- Bedrock Agents (where applicable)
Compute
- AWS Lambda
- Amazon ECS
- AWS Fargate
- Amazon EKS
Data
- Amazon S3
- Amazon Aurora PostgreSQL
- Amazon RDS
- Amazon DynamoDB
- Amazon OpenSearch Service
Security
- AWS IAM
- AWS KMS
- AWS Secrets Manager
- Amazon GuardDuty
- AWS Security Hub
- Amazon Inspector
- AWS Config
- AWS CloudTrail
- AWS WAF
Observability
- Amazon CloudWatch
- Prometheus
- Grafana
- Amazon OpenSearch Service
- AWS X-Ray (where applicable)
Networking
- Amazon VPC
- Application Load Balancer
- Amazon CloudFront
- Amazon Route 53
- Amazon API Gateway
Services are selected per project. Not every solution uses every service.
Agents should not have unrestricted access to production infrastructure.
Responsible & secure AI on AWS
Every Perixope agent runs with the minimum access it needs, behind guardrails, with its actions logged and, where required, approved by a person.
- Identity and access
- IAM roles with least privilege for every agent and tool.
- Encryption
- Data encrypted at rest and in transit with AWS KMS.
- Secrets
- Credentials kept in AWS Secrets Manager, never in prompts or code.
- Guardrails
- Amazon Bedrock Guardrails filter harmful, off-topic or sensitive content.
- Audit
- Every agent action recorded in AWS CloudTrail and application logs.
- Threat monitoring
- AWS Security Hub and Amazon GuardDuty watch the environment agents run in.
- Data isolation
- Data stays in your AWS account, inside your VPC and network rules.
- Human approval
- Required approval steps for any action with real impact.
How an agent’s action is controlled
Between the agent and your AWS account sit permission, policy and approval layers. The agent can only do what it has been allowed to do.
- 1AI agent
- 2Tool permission layer: only approved tools can be called
- 3Policy validation: the action is checked against your rules
- 4Human approval (where required)
- 5AWS API
- 6Action
- 7Verification: the result is confirmed and logged