Built for AWS teams that want Bedrock operations without extra routing or billing friction.
BedrockOps connects via a read-only cross-account IAM role and one-click Quick-Create CloudFormation, keeps customer operational data in Europe today, and starts through AWS Marketplace. The first meaningful finding shows up in the same session you connect — not after a long checklist.
The trust model is simple by design.
Before a team connects AWS it needs confidence on four points: a read-only connection, clear data use, predictable billing, and fast time-to-value. The operating boundary below is built to answer all four.
Delivered entirely on AWS
BedrockOps runs on AWS-native infrastructure in a single EU region — eu-west-3 (Paris) — with EU-hosted Postgres and Redis. Europe is the active region today; broader coverage comes in later versions.
Read-only IAM onboarding by default
A one-click Quick-Create CloudFormation link provisions a read-only cross-account IAM role in your account. Every scoped-write capability is a separate opt-in template you deploy explicitly — read-only is the default.
No in-path proxy
BedrockOps never sits in the request path and never proxies a Bedrock call. Data flows in one direction only — from your AWS account to BedrockOps.
Billing and trial through AWS Marketplace
The trial and all billing run through AWS Marketplace — predictable, AWS-native procurement with no separate web checkout.
One click to connect. Verification on every assumption.
The connection model is concrete: a read-only role provisioned by CloudFormation, a per-tenant External ID, and a verification step after every role assumption.
Quick-Create CloudFormation onboarding
Connecting an AWS account is one Quick-Create CloudFormation link that provisions the read-only cross-account role in your account. Nothing is deployed inside your account — no customer-side runtime, no Lambda.
A per-tenant External ID scopes the role
Each tenant gets its own server-generated External ID that scopes the trust relationship. It is never displayed in the dashboard and never leaves onboarding.
Every role assumption is verified
After every AssumeRole, BedrockOps calls GetCallerIdentity to confirm the assumed account and iam:GetRole to verify the trust-policy shape — a failed check aborts the assumption. Trust-policy drift is detected continuously, and repeated assume failures flag the account as access-revoked.
Less security friction. Less procurement friction.
Review a read-only connection model
Instead of evaluating a new traffic path, review a familiar cross-account IAM role.
Connect without changing routing
Onboard BedrockOps without changing request routing in production.
Use the familiar AWS Marketplace path
Stay on AWS-native procurement rather than a separate web billing workflow.
Europe is the active data region today.
Customer operational data stays in Europe today: SaaS-side compute runs in a single EU region — eu-west-3 (Paris) — and the operational database and cache are EU-hosted Postgres and Redis. The current regional scope is explicit so AWS teams can evaluate the operating boundary clearly before connecting production data.
Encryption is AWS-managed everywhere: SSE-S3 for buckets, SSE-SQS for queues, and provider-managed encryption at the database tier — BedrockOps never holds customer-managed encryption keys. Each team’s data is isolated at the database layer with PostgreSQL row-level security, and an append-only audit log is the durable record of every state change.
No proxy. No traffic reroute. No second checkout flow.
- No in-path runtime proxy
- No direct web checkout
- No vague data-boundary story
- No need to piece together billing outside AWS Marketplace
Start BedrockOps on an AWS-native path.
Start in AWS Marketplace, connect AWS with a read-only role, and use BedrockOps against real Bedrock production signals without changing live traffic flow.
Start 7-Day Trial On AWS Marketplace