
How Benchling secured multi-tenant AI agents with Amazon Bedrock AgentCore
How-To How to actually use this
What changed: Benchling now runs AI-generated scientific code in an isolated, multi-tenant environment using Amazon Bedrock AgentCore Code Interpreter inside a VPC, with DNS and network-level controls to prevent data leaks.
How to use it:
- Deploy your untrusted AI agent code in Bedrock AgentCore Code Interpreter configured in VPC mode.
- Attach Amazon Route 53 Resolver DNS Firewall rules to block outbound DNS requests to unauthorized endpoints.
- Enforce VPC endpoint policies that restrict network traffic to only approved services and IP ranges.
- Monitor tenant isolation logs to verify no cross-tenant data exfiltration occurs.
Good for: life sciences teams running AI-generated code across many customers.
Learn how Benchling built a defense-in-depth security architecture to run untrusted, AI agent-generated scientific code across thousands of life sciences tenants using Amazon Bedrock AgentCore Code Interpreter in VPC mode, combined with Amazon Route 53 Resolver DNS Firewall and VPC endpoint policies to block data exfiltration, including through DNS.
Read original article on Artificial Intelligence →




