Benchling Runs 600+ Agent Code Sessions Daily with Zero Incidents via Bedrock AgentCore Sandboxing
AWS ML Blog · rss · 2026-09-22
An AWS ML Blog deep dive explains how life-sciences company Benchling securely executes AI agent-generated code across thousands of tenants—600+ sessions daily, 250+ tenants weekly, zero security incidents. The defense-in-depth design uses a dedicated untrusted-code AWS account, Bedrock AgentCore Code Interpreter in VPC mode with no internet/NAT gateway, a three-tier Route 53 DNS Firewall policy (denylist, minimal allowlist, deny-all), per-job STS credential injection to avoid IAM role sprawl, and a continuous validation suite simulating exfiltration attempts. A directly reusable blueprint for multi-tenant LLM code execution isolation.
More from coding & agent
- Agentic LLMs Can Write Rust Code 2x-20x Faster Than State-of-the-Art Libraries — minimaxir · 2026-09-22
- Aethos X hits 94% on EnterpriseRAG-Bench at 42k files, nearing effective ceiling — rohanpaul_ai · 2026-09-22
- LlamaIndex adds per-field confidence scores to Extract for human-review triage — llama_index · 2026-09-22
- Superset for iPhone lets you control computer-side coding agents and ship PRs from your pocket — ycombinator · 2026-09-22
- Opus 5 spawns 17 subagents and burns 1.5M cached tokens on a simple lookup, Reddit user warns — tr14l · 2026-09-22
- Stripe's Emily Sands on agentic commerce: compute is the new cash, fraud is now full-funnel — every · 2026-09-22