Skip to content
context AI agents

Benchling secured multi-tenant AI agent operations using Amazon Bedrock AgentCore

only one source so far

Benchling deployed a security architecture for running code generated by AI agents across thousands of tenants on Amazon Bedrock AgentCore – with a separate AWS account, DNS Firewall and per-job credentials. According to the company, there have been no security incidents since launch.

Benchling, a provider of a software platform for life sciences, described a security architecture together with AWS for running code generated by AI agents across thousands of tenants. The solution is built on Amazon Bedrock AgentCore, specifically Code Interpreter in VPC mode, and addresses a situation where standard network controls block HTTP and restrict outbound ports, but DNS resolution often remains enabled without full visibility or control on the part of the operator.

According to the source, Benchling runs untrusted code in a separate AWS account isolated from the production environment, without an internet gateway or a NAT gateway, with a network group restricted to port 443 only. DNS queries pass through Route 53 Resolver DNS Firewall with three prioritized rules: blocking known malicious domains, allowing only explicitly listed endpoints, and blocking everything else. The only permitted network paths run through VPC endpoints for access to Amazon S3. Instead of one IAM role per tenant (which, according to the company, would lead to an unmanageable proliferation of roles), the system injects temporary credentials into each session via AWS STS, so data access scales dynamically according to the specific job.

According to Benchling, the system handles more than 600 code execution sessions daily across more than 250 tenants weekly, without a single security incident since deployment. The architecture also includes a test suite that continuously simulates data exfiltration attempts and verifies that the configured restrictions work.

Details can be found in the source article.

What changed

Why it matters

It demonstrates a concrete, operationally proven pattern for securely running code generated by AI agents where multiple customers share the same infrastructure – particularly relevant to companies in regulated industries that must demonstrably separate data belonging to individual clients and restrict even less obvious data leakage paths, such as DNS. Access through temporary per-job permissions instead of permanent roles per tenant also addresses a scaling problem faced by platforms with large numbers of customers.

Two audiences, two different impacts

What this means

01

For individuals

For architects and security engineers designing environments for running code generated by AI agents, this is a concrete network isolation design deployed in practice that can serve as a starting point for their own solution.

What to do Study the described architecture (a separate AWS account without an internet/NAT gateway, DNS Firewall with three priorities, temporary credentials via AWS STS) as a reference when designing an isolated environment for running…
More practical updates →
02

For a business

Companies running AI agents on sensitive data across many tenants gain a documented architectural pattern that, according to Benchling, reduces the risk of data exfiltration (including DNS vectors) while avoiding an unmanageable proliferation of IAM roles per tenant.

Risks and compliance
What to decide Consider a similar security pattern (a separate account for untrusted code, DNS Firewall, per-job access permissions instead of an IAM role per tenant) when designing your own multi-tenant platform for AI agents, especially in…
More business impacts →
AI agents Amazon Bedrock Benchling security multi-tenant vědecký kód

Check the original

Event sources

only one source so far · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
AWS Machine Learning Blog primary source · first detected How Benchling secured multi-tenant AI agents with Amazon Bedrock AgentCore