Skip to main content

Druva transforms data security using Amazon Bedrock AgentCore

Learn how Druva solved 68 percent of support issues without human intervention using Amazon Bedrock AgentCore.

Benefits

of support issues resolved

hallucinations

AI conversations powered across 3,000+ users in 4 months

Overview

As a provider of data security and cyber resilience solutions, Druva helps organizations strengthen cyber resilience by keeping data safe, improving readiness against cyber threats, and delivering fast, clean recovery when compromise or data loss is suspected.

To help customers navigate the full spectrum of incident response with greater clarity and confidence, Druva built DruAI, an agentic AI solution, by working alongside Amazon Web Services (AWS) and implementing Amazon Bedrock AgentCore, an agentic platform for building, connecting, and optimizing agents at scale. DruAI is a system of specialized agents that help organizations maintain resilience and, when needed, move from investigation to recovery more quickly, using guided, intelligent assistance to reduce manual effort and simplify complex workflows.

About Druva

Druva is a leading provider of data security solutions, helping more than 7,500 customers safeguard their businesses from cyber threats. Trusted by 75 of the Fortune 500, Druva strengthens cyber resilience with a fully managed, cloud-based software-as-a-service platform.

Opportunity | Simplifying data security using AgentCore

Managing complex data security and recovery workflows across cloud environments creates significant operational burden. Prior to Druva developing its multi-agent approach, customers had difficulties with manually piecing together insights from multiple sources to understand anomalous data, especially during high-pressure situations, such as security incidents. “It was a very manual process that involved lots of people,” says David Gildea, vice president of AI product at Druva. “Virtually any cyberattack in a company would become a high-stress situation.”

Earlier AI workflows and analytics could surface data, but customers still had to interpret results and decide next steps. Druva recognized that coordinating reasoning, action, and learning required a true agentic approach rather than just as-needed AI features. For Druva, adopting agentic AI meant giving customers faster, more intuitive ways to investigate backup anomalies, assess potential risk, and guide recovery actions while maintaining enterprise-grade security. For example, one global consulting firm uses DruAI to get instant answers and navigate data and documentation without digging through dashboards. DruAI saves the firm approximately 2 hours for every DruAI conversation while helping it make better decisions by surfacing actionable information more quickly.

While effective, Druva’s earlier approaches to build, train, and deploy AI models and custom RAG systems required constant infrastructure management. Seeking faster deployment and customizable agent behavior, Druva adopted AgentCore. This empowered Druva’s engineers to focus on embedding their data-security expertise into intelligent agents rather than maintaining underlying infrastructure.

Solution | Building a multi-agent system using agentic AI on AgentCore

Druva designed DruAI, a collection of specialized agents that work together to support cyber investigation, remediation, and recovery workflows. Instead of relying on a single response mechanism, DruAI coordinates multiple agents according to distinct roles. In production, DruAI coordinates eight to ten specialized agents, depending on the workflow. For instance, there are data agents that analyze telemetry and surface insights, help agents that guide users through troubleshooting and explain findings, and action agents that support recovery steps within defined boundaries. The multi-agent design empowers Druva to extend agent-driven assistance across more workflows while maintaining a simple user experience.

AgentCore helps Druva to focus on building agentic capabilities and workflows without managing the underlying infrastructure. AgentCore Runtime provides a secure, serverless hosting environment with session isolation and automated scaling for concurrent agent workflows, and AgentCore Gateway routes requests and securely connects Druva’s agents to internal APIs and tools, such as its unusual data activity service, reporting service, or Druva Cloud Platform capabilities. AgentCore Code Interpreter runs within these runtime sessions so that agents can carry out analysis tasks, such as interpreting data, generating reports, and supporting workflows. Additionally, AgentCore Identity authenticates DruAI’s agents to backend systems with scoped permissions, ensuring that investigation agents can query backup telemetry, help agents can access documentation, and action agents can run recovery workflows—all within defined security boundaries. Druva also deployed AgentCore Memory, giving AI agents the ability to remember past interactions. Using AgentCore Memory helps Druva’s agents learn from every customer interaction, adapting to whether each user prefers concise reports or detailed analyses of data investigations and adjusting tone based on their role—for example, compliance officer or IT admin.

DruAI accesses foundation models through Amazon Bedrock, a service for building generative AI applications and agents at production scale, giving Druva the flexibility to deploy models best suited to different agent tasks across investigation and recovery workflows. For example, for voice capabilities, Druva uses Amazon Nova Sonic, a speech-to-speech model for conversational AI. The company accesses Claude by Anthropic in Amazon Bedrock, using Claude Sonnet for its Supervisor agent and Claude Haiku as a decision layer across all agents.

The framework flexibility of AgentCore gave Druva the freedom to evolve its technical approach without infrastructure disruption. Druva initially used LangChain before transitioning to Strands Agents, which is designed to integrate seamlessly into the AWS environment—making it a strong fit for Druva’s architecture. This also simplified building multimodal capabilities like voice and screenshot analysis. Strands Agents also offers first-class integration with Amazon Bedrock Guardrails—which helps implement safeguards customized to application requirements—making it possible for DruAI agents to protect customers from threats like prompt injection attacks and malicious inputs.

Outcome | Resolving 68 percent of support queries with DruAI

Since launching DruAI, Druva has transformed how customers approach data security challenges. Cyber investigations that previously took 30–⁠60 days are now completed in minutes through natural language conversations. Today, 68 percent of customer issues—such as investigation guidance and backup troubleshooting—are resolved through agent workflows, and when support teams do assist, resolution is 58 percent faster. Adoption has also grown rapidly, with over 17,500 AI conversations across more than 3,000 users—representing 55 percent growth in use over a 4-month period—with no hallucinations. For Druva’s development team, using AgentCore virtually doubled productivity by removing infrastructure management burden and facilitating weekly releases of AI capabilities.

Looking ahead, Druva is constantly expanding capabilities and use cases for DruAI, and it recently introduced multimodal capabilities, including voice interactions and screenshot analysis—helping users interact more naturally with the platform and quickly surface insights from visual or spoken inputs. The company is also exploring how using AgentCore Gateway can expand DruAI capabilities through MCP servers, which act as connectors to customer systems and data sources. This would make it possible for DruAI to access and act on information across existing customer environments like AWS and data centers, supporting more context-aware assistance and reducing the need for manual data-gathering. As that work continues, AWS and AgentCore remain central to Druva’s progress. “This link is key because we’ve relied on AWS knowledge of agentic AI, and AWS has been at it a long time,” says Gildea. “What AgentCore helped us build is unlike virtually anything out there.”

Architecture Diagram

Druva’s solution architecture, with reference to AWS services.

Missing alt text value

Get Started

Organizations of all sizes across all industries are transforming their businesses and delivering on their missions every day using AWS. Contact our experts and start your own AWS journey today.

Contact Sales

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages