Overview
Public sector and regulated organisations are already experimenting with AI, but progress often stalls before production. Governance, compliance, and risk concerns make it difficult to deploy AI safely in live environments, especially where legacy systems and constrained architectures limit deployment options and accountability is unclear. AI Spark addresses this with a governed entry point for AI deployed into the customer AWS environment. It establishes visibility, guardrails, and accountability without requiring system replacement or re-platforming. This enables organisations to apply AI safely while retaining full control of infrastructure, security, and network boundaries. AI Spark is designed for partner-led delivery and supports a controlled path forward. Customers can start safely, establish governance early, and assess next steps once the environment is live.
Highlights
- Governed entry point for AI in regulated and security-sensitive environments.
- Deployment into customer AWS account for full infrastructure and security control.
- Enables AI progress without replacing or re-platforming existing systems.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/unit/hour |
|---|---|---|
Hours | Container Hours | $82.19178082 |
Vendor refund policy
Please contact TomorrowX for refund & policy https://tomorrowx.dev/get-help/
Refer to the AWS Marketplace Buyer Guide for further details regarding:
- Refunds for AWS Marketplace products https://docs.aws.amazon.com/marketplace/latest/buyerguide/buyer-refunds.html
- Canceling a container subscription https://docs.aws.amazon.com/marketplace/latest/buyerguide/cancel-subscription.html#cancel-container-subscription
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
CAP Agent - ECS Fargate
- Amazon ECS
Container image
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
fix: use MeterUsage API for Marketplace PID1 dimension fix: CFT scan - remove default 0.0.0.0/0 CIDR values, require explicit customer input fix: CFT scan - add explicit egress rules to all security groups fix: CFT - resolve EFS DependsOn errors when EFS is disabled docs: add IAM resource disclosure to usage instructions
Additional details
Usage instructions
Quick Launch
Deploy a CAP Agent using CloudFormation (change the region in your AWS Console to your preferred region first): https://console.aws.amazon.com/cloudformation/home#/stacks/create/review?templateURL=https://public-tomorrowx-s3.s3.eu-central-1.amazonaws.com/cap-agent-marketplace.yaml&stackName=cap-agent
- Select your VPC and 2+ subnets in different availability zones
- Set CIDR ranges for web, management, and database access. Set to x.x.x.x/32 to allow one specific IP address, 0.0.0.0/0 to allow all IP addresses, or another CIDR range
- Set a database master password (8-128 characters)
- Acknowledge IAM resource creation (see AWS Resources Created below)
- Click "Create stack" - deploys in ~5 minutes
- Go to CloudFormation > Stacks > cap-agent > Outputs for your Agent URL and connection details
Connecting Your CAP Console
- Open CAP Console > Administration > Agent Definitions > Create New PDA
- Set Host to the task public IP (from Outputs tab)
- Set Port to 20001
- Set Task ARN, Amazon ALB Target Group ARN, Amazon Access Key, and Amazon Secret Key from the Outputs tab
- Deploy extensions and rulesets via Console
AWS Resources Created
This template creates the following IAM resources:
- TaskExecutionRole (IAM Role): Allows ECS Fargate to pull container images from ECR and read database credentials from AWS Secrets Manager.
- TaskRole (IAM Role): Grants running containers access to CloudWatch Logs, the stack's S3 snapshot bucket, ECS Exec for debugging, and AWS Marketplace metering.
- SnapshotScriptLambdaRole (IAM Role): Allows a one-time Lambda function to deploy a helper script to the S3 bucket during stack creation.
- DeployUser (IAM User) and DeployUserAccessKey (IAM Access Key): Scoped credentials for CAP Console's remote agent deployment feature (rolling updates). The access key and secret key are stored securely in AWS Secrets Manager (secret name: <stack-name>/deploy-user-credentials). The user's policy is restricted to ECS task discovery (scoped to this stack's cluster) and ALB target group operations. Retrieve credentials via the DeployUserCredentialsCommand in the stack Outputs tab. To Remove
Delete the CloudFormation stack - all resources are cleaned up automatically.
Documentation: https://docs.tomorrowx.com Support: help@tomorrowx.dev
Resources
Vendor resources
Support
Vendor support
Support is delivered through partners, with TomorrowX providing platform support and specialist advisory capability where applicable. Support levels scale by license tier and are confirmed during onboarding. The customer retains control of infrastructure and networking within their AWS environment. For platform support requests, please visit
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.