Overview
Why this exists
Security and procurement teams increasingly block external AI SaaS tools outright, while data residency and sovereignty requirements keep tightening — AWS launched a dedicated European Sovereign Cloud in January 2026 specifically to meet EU-only data requirements. But the same organizations already trust, monitor and govern their own AWS accounts. This service gives them a capable AI assistant without asking them to change who controls their data.
What we deliver
- A generative AI assistant deployed and operated inside a controlled AWS account that you own, using foundation models served through Amazon Bedrock.
- Access over VPN or another private, controlled channel only. No public internet exposure.
- Governance controls that stay with your team: model access, spend limits and budget alerts, and audit logging through AWS CloudTrail.
- Setup, configuration, hardening and ongoing operation handled by us.
How we deliver
- Design — target account, network path, private access method, model selection and region, driven by your data-residency requirements.
- Deploy — the environment is built in your account as infrastructure-as-code, with the access path and guardrails in place.
- Operate — ongoing operation, monitoring, model and configuration updates, and periodic review of usage and spend.
Who this is for
Regulated or security-conscious organizations already on AWS, particularly those newly subject to EU or regional data-residency rules, that want AI capability without introducing a new external data processor.
Recommended next step
Customers typically pair the deployment with a 40-hour support block from "Adamass AWS Architect as a Service", used across the first two months of live operation — for prompt and workload design, access policy, cost tuning and enabling the internal team. It can be included in the same private offer as the deployment.
AWS services potentially provisioned in your account
- Amazon VPC
- VPC interface endpoints (AWS PrivateLink)
- Route 53 private hosted zones
- Security groups and network ACLs
- AWS Client VPN — only where no existing private path exists
- Application Load Balancer — internal scheme
- AWS Certificate Manager
- Amazon ECS on AWS Fargate
- Amazon ECR
- AWS Lambda
- Amazon Bedrock
- Amazon Bedrock Guardrails
- Bedrock model invocation logging
- Amazon S3
- Amazon DynamoDB
- AWS KMS — customer-managed keys
- AWS Secrets Manager
- Amazon CloudWatch
- AWS CloudTrail
- AWS Config
- AWS Budgets and Cost Anomaly Detection
- AWS Systems Manager
- Amazon Bedrock Knowledge Bases
- Amazon OpenSearch Serverless
AWS charges
This service does not include your AWS infrastructure or model inference costs. Amazon Bedrock usage and all other AWS resources deployed in your account are billed to you by AWS separately from this AWS Marketplace transaction. We configure budgets and alerts so that consumption is visible from day one.
Highlights
- Runs entirely inside your own AWS account and your own security boundary — no data leaves it, and no new external vendor holds your data.
- Private access only, over VPN or another controlled channel. Never published to the open internet.
- Governance stays with your team — spend limits, model access and audit logs — while we handle deployment, configuration and ongoing operations.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.