AgentCore Production Hardening on AWS - HIPAA + SOC 2 Controls
Kriv AI · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
**Amazon Bedrock AgentCore became HIPAA-eligible on February 10, 2026, opening PHI-touching agent deployments under an executed AWS BAA. There is still no fixed-fee transparent-pricing production-hardening SKU on AWS Marketplace pairing AgentCore with HIPAA Security Rule AND SOC 2 Type II. Kriv's N27 closes that gap in a ~6-month first-mover window.**
AgentCore HIPAA eligibility alone is not sufficient. Its six primitives—Runtime, Identity, Gateway, Memory, Observability, and Code Interpreter/Browser sandbox—must be configured, logged, isolated, and documented to meet HHS OCR scrutiny, SOC 2 Type II (AICPA TSC), cyber-insurance attestation, and Customer TPRM review. Most enterprises fail here:** AgentCore POC works in sandbox but fails CISO, HIPAA Privacy Officer, or TPRM production approval.** Required controls include tenant memory isolation, audit trails (CloudTrail + Bedrock Model Invocation Logging + AgentCore logs), state recovery, multi-step observability, OWASP LLM Top 10 defenses, cost predictability, and multi-region DR.
Show the rest of the publisher’s description (6 more lines)
Rackspace **LegalMind** uses AgentCore primitives but is vertical (legal). **IBM Consulting Advantage** + **Adastra Agentic AI** + **DevSecOps Inc. HIPAA-Compliant Infrastructure** + **IBM Agentic Cloud Transformation Accelerator** lack AgentCore + HIPAA / SOC 2 framing. Big-Four SI runs off-Marketplace: PwC announced $400M AWS agentic security/compliance collaboration; Deloitte agentic SOWs $250K–$1.5M pilot / $2M+ scale; Accenture 450+ agents at $150K–$750K production hardening. **No Marketplace listings pair AgentCore with HIPAA or SOC 2 today. N27 is first*
**Reference architecture.** Runtime hardening (sandboxed Code Interpreter + Browser; per-session KMS CMK envelope encryption; ephemeral storage zeroized; session isolation). Identity (OAuth 2.1 + JWT + mTLS; IAM Identity Center + SAML/OIDC; RBAC + ABAC; tenant isolation via tags + SCPs; MFA). Gateway (WAF + Shield Advanced + API Gateway throttling + request signing; PrivateLink). Memory (short + long-term per-tenant isolation; KMS; Macie PII/PHI discovery; 6-yr HIPAA / 3-yr SOC 2 retention). Observability (OpenTelemetry + X-Ray; tool-use decisions logged; CloudWatch + QuickSight FinOps). Bedrock Guardrails (PHI/PII, denied topics, medical-misinformation, fair-lending, bias/fairness; override with dual-approval). Audit Trail (CloudTrail + Bedrock Model Invocation Logging + custom AgentCore logs → S3 Object Lock; hash-chained tamper-evident). Recovery (state checkpointing; multi-region DR active-passive HIPAA, active-active Enterprise). Incident Response (AI runbooks; CloudWatch + EventBridge + SNS to SOC). Security Monitoring (GuardDuty, Security Hub, Macie, Inspector, Config). Secrets Manager + KMS auto-rotation. BAA Verification in Week 1.
**HIPAA Security Rule mapping** §164.308(a)(1–8) administrative; §164.310 physical (AWS shared responsibility); §164.312(a–e) technical; §164.316 6-yr retention. **SOC 2 Type II** CC1–CC9 + scoped Availability / Confidentiality / Processing Integrity / Privacy.
**Week-by-week.** W1 Kickoff + gap analysis + AWS BAA verification + CISO / HIPAA / TPRM pre-approval. W2 Landing zone + audit baseline. W3 Identity + Gateway hardening + pentest smoke test. W4 Memory + Guardrails + Macie. W5 Observability + audit validation. W6 Recovery + DR + IR, Foundation closes (30-day warranty). W7 Standard, HIPAA or SOC 2 evidence + CPA/EAO handoff (60-day warranty). W8 Enterprise, load testing + multi-agent isolation + 90-day hypercare.
**Three tiers.** Foundation $75K (6 wk; 1 agent; SOC 2-ready; active-passive DR; 30-day warranty) for AI-native Series B–E + Fortune 1000 first internal pilot. Standard $150K (7 wk; up to 3 agents; **HIPAA OR SOC 2** evidence package; tenant-isolation hardening; 60-day warranty) for mid-sized healthcare, payers, life sciences, banks, BDs, insurers. Enterprise $275K (8 wk; up to 5 agents; **HIPAA + SOC 2 combined**; memory isolation validation; multi-region active-active DR; 90-day hypercare) for large regulated, G-SIB banks, top-25 payers, top-25 pharmas. Optional Extra Agent $40K each. EDP-eligible — production hardening engagement fees ($75K–$275K) count toward your AWS Enterprise Discount Program commitment (up to 25%). AWS + Anthropic + Bedrock consumption costs are billed separately. Contact info@kriv.ai to structure a private offer against your EDP or PPA.
**Important disclosures.** Kriv is NOT a HITRUST EAO, CPA firm, ISO body, or FDA-registered manufacturer, issues no HIPAA / SOC 2 / HITRUST / ISO certifications. Kriv operates as Customer's BA where PHI flows (BAA required). Does NOT develop Customer agent business logic, hardens surrounding infrastructure. Does NOT operate agents post-deployment (unless Managed Service retainer). No legal / regulatory / compliance advice. AWS + Anthropic + Bedrock consumption separate. No approval outcome guarantee. No AgentCore API stability guarantee. Anthropic CPN membership does not constitute endorsement.
Highlights
Highlighted by the publisher on AWS Marketplace.
First AgentCore + HIPAA / SOC 2 production-hardening SKU on AWS Marketplace, AgentCore HIPAA-eligible February 10, 2026; ~6-month first-mover window. All six AgentCore primitives hardened on Customer's AWS account: Runtime (sandboxed Code Interpreter + Browser + per-session KMS CMK envelope encryption + ephemeral storage zeroed), Identity (OAuth 2.1 + JWT + mTLS + IAM Identity Center + MFA), Gateway (WAF + Shield Advanced + rate limiting), Memory (per-tenant isolation + KMS + Macie).
AgentCore Observability (OpenTelemetry + X-Ray + CloudWatch + QuickSight FinOps dashboards) + Bedrock Guardrails (PHI/PII + denied topics + medical-misinformation + fair-lending + bias/fairness filters with dual-approval override) + Audit Trail (CloudTrail + Bedrock Model Invocation Logging + custom AgentCore structured logs to S3 Object Lock, 7-year HIPAA / 3-year SOC 2 retention, hash-chained tamper-evident) + multi-region DR (active-passive Foundation/Standard; active-active Enterprise).
HIPAA §164.308 / §164.312 / §164.316 + SOC 2 Type II Common Criteria (CC1–CC9) evidence mapping per tier; CPA firm (SOC 2) or HITRUST EAO handoff package. Three tiers: $75K Foundation (1 agent, SOC 2-ready, 6 weeks) for AI-native Series B–E; $150K Standard (3 agents, HIPAA OR SOC 2, 7 weeks) for mid-sized regulated-industry; $275K Enterprise (5 agents, HIPAA + SOC 2 combined, active-active DR, 90-day hypercare, 8 weeks) for G-SIB / top-25 payers / top-25 pharmas.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
3 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

