BlueRock Security provides embedded runtime security into your cloud Linux and container images. Simply select the distribution for your instances or nodes and launch a secure by default runtime to deploy your applications on top of. BlueRock minimizes the overhead of vulnerabilty remediation by protecting against ~70% of both known and unknown vulnerability exploits saving hours of time for developers.
BlueRock Security gives organizations a secure by default compute foundation to counter AI speed attacks and save time for your developers. The solution provides Runtime Reachability Intelligence (RRIQ) to identify what libraries and code paths actually run mapped to exploitable CVEs to help prioritize the most important fixes. This helps minimize false positives from SCA and static analysis scans and help control the endless churn of the vulnerability scan and patch process.
This BlueRock Amazon Linux 2023 image offers the following benefits:
Visibility into which libraries and code paths actually run in your app environments.
Reduction in your vulnerability patch list by 70 - 90% saving time spent on false positive vulnerabilities on a continual basis.
Evidence-based reachability reports that align dev and security on what to fix first.
Runtime protection for apps containers and nodes without legacy bolt on agents.
Java and Python App runtime guardrails to detect and block against Java and Python deserialization path traversal and other package and framework vulnerabilities.
The BlueRock Compute Firewall delivers real-time attack prevention to protect app container and host runtime environments. Always-on and transparent BlueRock removes the need to deploy yet another security agent and protects workloads without requiring developer code changes.
Instead of searching for needles in noisy telemetry haystacks BlueRock proactively enforces runtime invariants - precise guardrails capable of disrupting entire classes of attacker exploit chains. This invariant-based approach flips the script on detect and respond clearly defining what should never happen in uncompromised workloads.
This approach enables BlueRock to see and stop attacker behavior and avoid false positives. It does not guess. It blocks only definitively malicious actions. And it does so with little to no performance impact.
Highlights
Embedded runtime security. Secure by default - no installation required
Save developers time by blocking~70% of unknown and known exploits to reduce the overhead of patching
Provides security teams with in-depth visibility of exploit attempts and configuration drift.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing dimension billed as a contract. You pay for BlueRock Compute Runtime Security, measured in units. The product runs as an EC2 image you deploy on your own AWS infrastructure. It provides runtime observability and guardrails for agent execution, tracing how agents interact with tools and connected systems. Since there is a single dimension, pricing does not scale across tiers or instance sizes here. You commit to the contract and the unit-based rate shown in the pricing table.
Top-of-mind questions for buyers
What does one unit of BlueRock Compute Runtime Security cover?
A unit maps to the compute runtime security capability running on the EC2 image you deploy. It observes agent execution and applies guardrails at runtime across tools, MCP servers, and downstream systems. The unit reflects the runtime protection layer active on your own AWS infrastructure.
Do we need to change our agent code or infrastructure to run this?
No agent code changes are required. BlueRock connects at the execution layer instead of adding logging hooks or instrumentation. You deploy on your own AWS infrastructure using CloudFormation, which takes under five minutes. Observability runs alongside execution without meaningfully affecting workflow performance.
What runtime protections and controls are included in this contract dimension?
You get real-time observability of the agent action path, plus context-aware guardrails applied at execution. Controls follow execution across tools, MCP servers, and downstream systems within a single run. It also includes agent process and filesystem isolation and detection of tool, data, and execution drift.
bluerock.io+3
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
The following AWS services and resources are deployed with the CloudFormation template:
EC2 instance with EBS storage
IAM role with S3, logs, and IAM permissions
VPC with subnets
S3 bucket for policy storage
CloudWatch Log Group for events
Internet Gateway for instance access
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
The BlueRock Agentic Sandbox and Secure MCP Server provides AI development teams with a production-ready environment to build, test, and operate MCP-based agentic workflows on AWS.
Bluerock TMS is a solution that helps businesses in the transportation industry streamline logistic operations and delivery processes with our Distribution solution having focus on detailed planning and route optimization including embedded driver app.
Bluerock TMS is a solution that helps businesses in the transportation industry streamline logistic operations and delivery processes. Our TMS solution supports manufacturing companies and logistics experts (3PL, 4PL, ...).
BlueRock Security provides embedded runtime security into your cloud Ubuntu Linux and container images. Simply select the distribution for your instances or nodes and launch a secure by default runtime to deploy your applications on top of. BlueRock minimizes the overhead of vulnerabilty remediation by protecting against ~70% of both known and unknown vulnerability exploits saving hours of time for developers.