Overview
Overview
AI For You Workbench is a secure, multi-model generative AI platform purpose-built for higher education and deployed entirely within your own AWS account. It gives your institution one governed interface to the leading AI models while keeping data, identity, and cost fully under your control. Faculty, staff, students, and researchers get modern AI tools, while IT and compliance teams get the isolation, auditability, and governance an academic environment demands.
One platform, every model
Access frontier models from Anthropic (Claude), OpenAI (GPT), and Google (Gemini) through a single normalized gateway. Administrators choose which models are available, set per-department budgets and rate limits, and monitor spend in real time. Because model access is centralized, you can adopt new models as they launch without re-integrating, and route sensitive workloads only to vendors that meet your data-retention and compliance requirements.
Knowledge, RAG, and data connectors
Turn your institution's own content into grounded, citable answers with retrieval-augmented generation (RAG). Users build knowledge banks from uploaded documents (PDF, Word, PowerPoint, Excel, and text) and from a growing library of connectors:
- Content sources: Amazon S3, Azure Blob, OneDrive, SharePoint, Google Drive, Google Cloud Storage, Confluence, Notion, Box, and Dropbox.
- Databases: PostgreSQL, MySQL, and SQL Server, with read-only natural-language querying so non-technical staff can ask questions of institutional data in plain English.
Administrators assign connectors to department knowledge banks, and disabling a source cleanly removes its content, keeping answers current and access scoped.
Assistants, research, and content tools
Beyond chat, build custom assistants tailored to courses, departments, or research groups; generate and summarize content; and give research teams programmatic API access with scoped keys. Conversations, assistants, and knowledge stay owned by the institution.
Compliance and security by design
The Workbench is engineered for regulated academic data. It is aligned with FERPA, HIPAA, SOC 2, and GDPR, and enforces protection at every layer:
- Identity: SSO via OpenID Connect (Amazon Cognito) with MFA and role-based access control mapped to institutional roles.
- Isolation: a dedicated single-tenant deployment (a walled garden) with database-enforced tenant isolation, so data never crosses boundaries.
- Encryption: AES-256 at rest with per-tenant KMS keys, and TLS in transit.
- Auditability: comprehensive audit logging of data access and administrative actions, with PII kept out of logs.
Sensitive data is only ever routed to model vendors that meet your retention and BAA requirements, enforced automatically by the platform.
Deploys in your AWS account
Delivered as an AWS CloudFormation template, the Workbench provisions a complete, production-ready stack in your account: a dedicated VPC, Multi-AZ PostgreSQL (with pgvector) and Redis, auto-scaling ECS Fargate services, a load balancer, KMS keys, and Cognito. Database migrations run automatically on deploy, and high-availability and cost-lean sizing options let you match spend to each environment. Nothing leaves your tenant, and you keep full ownership of your data and infrastructure.
Highlights
- Multi-model AI, one governed interface: Give faculty, staff, and students secure access to leading models from Anthropic, OpenAI, and Google, with per-department budgets, rate limits, and real-time cost controls.
- RAG over your institution's own data: Build knowledge banks that deliver grounded, citable answers using retrieval-augmented generation and connectors for S3, SharePoint, OneDrive, Google Drive, Confluence, Box, Dropbox, and SQL databases.
- Compliant and single-tenant in your AWS account: FERPA, HIPAA, SOC 2, and GDPR aligned, with SSO, role-based access control, per-tenant isolation, KMS encryption, and full audit logging. Nothing leaves your tenant.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
- Monthly subscription
- $20,000.00/month
Vendor refund policy
No refunds
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
AWS CloudFormation deployment (single-tenant, in your AWS account)
- Amazon ECS
Container image
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Initial release of AI For You Workbench, a secure, multi-model AI platform for higher education, deployed entirely in your own AWS account.
Highlights
- Multi-model AI: governed access to leading models from Anthropic, OpenAI, and Google through one gateway, with per-department budgets and rate limits.
- Knowledge and RAG: ground answers in your own documents with retrieval-augmented generation, organized into department knowledge banks with fine-grained access control.
- Data connectors (natural-language querying): PostgreSQL, MySQL, SQL Server, Amazon Redshift, Snowflake, and Google BigQuery, read-only.
- Content connectors: Amazon S3, Azure Blob, Google Cloud Storage, OneDrive, SharePoint, Google Drive, Confluence, Notion, Box, and Dropbox.
- Assistants and APIs: build custom assistants, generate and summarize content, and issue scoped API keys for researchers.
- Security and compliance: Cognito SSO with MFA, role-based access control, per-tenant isolation, KMS encryption at rest, TLS in transit, and full audit logging. Aligned with FERPA, HIPAA, SOC 2, and GDPR.
- One-click AWS deployment: an AWS CloudFormation template provisions a dedicated VPC, Multi-AZ PostgreSQL (pgvector), Redis, ECS Fargate, an Application Load Balancer, and Cognito. Database migrations run automatically on launch.
Additional details
Usage instructions
Prerequisites
- An AWS account with permission to create IAM roles, VPC, RDS, ElastiCache, ECS/Fargate, ELB, KMS, Cognito, Lambda, and Secrets Manager resources.
- Recommended: a public hostname you control and an AWS Certificate Manager (ACM) certificate in the deployment region that covers it. Amazon Cognito requires HTTPS for sign-in.
- Launch the stack
- From this deployment option, launch the provided AWS CloudFormation template. The container image parameters are pre-filled with the published images.
- Or deploy the template directly: https://s3.us-east-1.amazonaws.com/cft.businesscompassllc.com/aiforyou/Workbench/aifu-workbench-marketplace.yaml
- Set parameters
- DeploymentTier: "prod" (Multi-AZ high availability) or "dev" (single-AZ, lower cost).
- PublicHostname and CertificateArn: your hostname and ACM certificate ARN (required for a working SSO login).
- Adjust database, cache, and Fargate sizing and the Cognito MFA policy as needed. AppImage and WebImage are pre-filled.
- Acknowledge that the stack creates named IAM roles, then create the stack.
- Point DNS at the load balancer
- Create a DNS record for your PublicHostname pointing to the Application Load Balancer DNS name shown in the stack Outputs (AlbUrl).
- Create your first administrator
- In the Amazon Cognito user pool created by the stack, create a user and add them to the "system_admin" group. Cognito emails a temporary password.
- Sign in
- Open https://your-hostname/ and sign in through the hosted login. Users enroll MFA on first sign-in.
Notes
- Database migrations run automatically on stack create and update. No manual migration step is required.
- All data stays in your AWS account. Secrets are stored in AWS Secrets Manager and encrypted with a per-deployment AWS KMS key.
- To upgrade, update the stack with new AppImage and WebImage values; migrations re-run automatically.
For detailed documentation, see the product support resources on the listing page.
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.