Security controls by project for four samples centered on Amazon Bedrock and Amazon Bedrock AgentCore: what to review before production, where each project's security documentation lives, and how to report a vulnerability.
Security controls by project
Each cell states the control as the project ships it, with a link to the file that says so. Postures are coarse on purpose; read the cell text before relying on a control.
EnforcedActive in the deployed reference implementation.
Advisory by defaultPresent, but logs or opt-in rather than blocking until you switch it on.
IllustrativeTaught or demonstrated; not positioned as a production control.
Outside envelopeDocumented by the project as outside its tested support envelope.
Not applicableNot part of this project.
The table is wider than the screen. Scroll it sideways to see every project.
CUSTOM_JWT authorizer validates Cognito access tokens against the OIDC discovery URL; the demo app client allows only the IAM-gated ADMIN_USER_PASSWORD_AUTH flow.
Scope-based RBAC ships advisory by default (RBAC_ENFORCE=false); owner-scoped tenant isolation is always enforced; Cedar ENFORCE applies per Policy node.
The registry data stack creates a customer-managed KMS key for the DocumentDB store; see the CloudFormation templates under static/cfn for the other stores.
DynamoDB tables use AWS-managed SSE; S3 buckets block public access and enforce SSL; the SNS topic uses SSE with enforced TLS; CloudFront requires TLS 1.2.
WAF web ACL (CLOUDFRONT scope in us-east-1, REGIONAL on the Cognito pool elsewhere); the control plane has no VPC egress; runtimes can use VPC egress through named profiles; optional PrivateLink ingress add-on.
Private VPC with three AZs and private-isolated subnets only (no internet gateway, no NAT) reaching AWS services through interface endpoints. The live-validated Workstream Runtime stack sets networkMode PUBLIC; VPC network mode is documented as a follow-on. VPC Lattice private endpoints are outside the envelope.
Structured request_audit and request_blocked records per call; refused calls are audited; the user is the Cognito sub; argument values are never logged.
Managed Bedrock Guardrail via ApplyGuardrail on requests (prompt attack, content filters) and responses (PII anonymized). It uses the unpinned DRAFT version, and a guardrail API error is logged while the local regex controls still apply.
Before deploying any of these projects to a production environment, review:
IAM policies and trust relationships in each stack
Network configuration and egress patterns
Data classification and retention requirements
Compliance obligations for your organization
Cost projections and budget alerts
Backup and disaster recovery plans
Incident response procedures
Known limitations documented in each project README, collected on the support envelope page
Security documentation on this site
Rendered documents open on this site. README sections open on the rendered README page, with a GitHub link beside each. Files the site does not render link straight to GitHub.