Overview

Product video
AI agents now call tools, run code and touch production systems on their own. Guardrails and behavioral monitoring score risk and let most actions through. VAREK decides before execution: each action is checked against policy, and anything VAREK cannot prove is allowed is refused.
VAREK Enterprise runs on Amazon Linux in your own account. The Warden enforces each verdict at the kernel boundary through seccomp-BPF and seccomp user-notify, so a compromised or confused agent cannot talk its way past a refusal. Every SATISFIED verdict carries a certificate that an independently written checker must accept before the action runs.
Each decision is recorded in a SHA-256 hash chain with Ed25519-signed checkpoints, and records export as CycloneDX 1.6 authorization evidence for auditors. The image includes maintained policy packs mapped to HIPAA Section 164.312 technical safeguards and SOC 2, plus enterprise support with security advisories. Apart from the AWS License Manager entitlement check, VAREK sends no data out of your account; off-host anchoring of the authorization log is optional and runs only when you configure it. The underlying runtime is open source under the MIT license.
Highlights
- Deny by default: only actions proven SATISFIED execute; UNSATISFIED and UNKNOWN are refused at the Linux kernel boundary.
- Evidence auditors accept: signed, hash-chained verdicts export as CycloneDX 1.6, with policy packs mapped to HIPAA Section 164.312 and SOC 2.
- Works with any agent stack, whether Amazon Bedrock AgentCore, open-source frameworks or in-house code, because enforcement happens on the host, not in the model.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
VAREK Enterprise Tier A (Standard) | VAREK Enterprise with standard support: 8 business hour response for critical issues, policy packs, evidence export and security advisories. | $75,000.00 |
VAREK Enterprise Tier B (Priority) | VAREK Enterprise with priority support: 4 business hour response for critical issues with a video call on request, policy packs, evidence export and security advisories. | $150,000.00 |
Vendor refund policy
Refund requests are reviewed case by case. Email support@soberagents.ai with your AWS account ID and the reason; we respond within two business days. Approved refunds are issued through AWS Marketplace.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
First release of VAREK Enterprise on AWS Marketplace (VAREK 1.21.1 on Amazon Linux 2023, x86_64).
Additional details
Usage instructions
Launch and connect
-
Launch the AMI on an x86_64 instance, t3.medium or larger, with your own EC2 key pair.
-
Connect over SSH as ec2-user. Password login is disabled. The recommended security group allows SSH from any address; restrict it to your own IP range before launch.
-
To use your VAREK Enterprise subscription, attach an IAM instance role that allows license-manager:CheckoutLicense. Without it, VAREK runs as VAREK Core.
Set up (about five minutes)
varek policy list # shows the policy packs sudo varek init --pack hipaa # or soc2, healthcare, finance, ... sudo varek doctor # confirms the host is ready sudo varek preflight --run # a real trial run, then its audit
Before production, replace the example paths and addresses in /etc/varek/policy.txt with your own. Then run varek policy check.
Run your agent
sudo varek run -- python3 /path/to/your_agent.py
Every action the agent takes is decided before it executes. Only SATISFIED actions run; UNSATISFIED and UNKNOWN actions are refused, and the agent receives a permission error.
Review and produce evidence
sudo varek refusals # what was refused, and which policy line decided it sudo varek audit # re-checks certificates, hash chain and signatures sudo varek export # signed CycloneDX 1.6 authorization evidence
Verdict streams are written to /var/log/varek. Evidence files can be verified by anyone holding /etc/varek/log.key.pub, using varek export --verify FILE --pubkey log.key.pub.
Network and data
VAREK sends no data out of your instance. Off-host anchoring of the authorization log is optional and runs only if you configure it. The license check calls AWS License Manager in your account.
Help
varek --help lists every command. Documentation: https://varek-lang.org . Support: support@soberagents.ai .
Resources
Vendor resources
Support
Vendor support
Email support@soberagents.ai with the severity (1 Critical, 2 High or 3 Normal) in the subject line. Support hours are 8:00 to 18:00 US Central time, Monday to Friday, excluding US federal holidays.
Response targets for Tier A (standard): 8 business hours for critical issues, 2 business days for high, 3 business days for normal. Tier B (priority): 4 business hours for critical issues with a video call on request, 1 business day for high, 2 business days for normal.
Every subscription includes the HIPAA and SOC 2 policy packs with updates, CycloneDX evidence export guidance, onboarding sessions, and security advisories delivered before public disclosure. SAI supports the current and previous minor release of VAREK Enterprise on Amazon Linux 2023.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.