Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Hermes AI Agent turns an EC2 instance into a self-hosted AI assistant that customers can operate through Telegram. This is a repackaged open source software product wherein additional charges apply for independent AWS packaging, validation, security hardening, release automation, and support. Hermes Agent is developed by Nous Research and distributed under the MIT license; this product does not claim authorship of the upstream project.
The production-ready AMI includes a pinned, published Hermes Agent release, its Telegram gateway dependencies, UFW default-deny inbound firewalling, fail2ban SSH protection, SSH key-only authentication, unattended security upgrades, network sysctl hardening, gp3 root storage with encryption available at launch, and required IMDSv2. The gateway runs as a systemd service with customer configuration and state stored under /home/ubuntu/.hermes. No customer credentials are baked into the AMI.
Show the rest of the publisher’s description (6 more lines)
Getting started after launch:
- Restrict TCP 22 to a trusted CIDR and connect as ubuntu with your EC2 key pair.
- Set your model-provider API key, model selection, Telegram bot token, and allowed Telegram user ID.
- Run sudo /opt/hermes/bin/provision-hermes.sh and verify systemctl status hermes-gateway.
The product is fully functional after configuration and has no product-imposed time or usage restriction. An internet connection, a supported third-party model-provider account, and a Telegram bot are required and are disclosed external dependencies. The optional five-day free trial changes only the software billing and automatically converts to the paid hourly offer; it does not enable a separate trial or evaluation edition.
The software charge is USD 0.02 per running instance-hour. EC2, EBS, data transfer, Telegram connectivity, and third-party model-provider usage are charged separately by their providers.
Highlights
Highlighted by the publisher on AWS Marketplace.
Ready to configure: Hermes Agent and its Telegram gateway dependencies are pinned and pre-installed; add your own model-provider and Telegram credentials after launch.
Production-operated foundation: Hermes runs as a systemd service with release markers, persistent customer state, automated security updates, and daily Marketplace-copy health checks.
Hardened from first boot: UFW, fail2ban, key-only SSH, gp3 storage with encryption available at launch, unattended security upgrades, and required IMDSv2 reduce the host attack surface.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Plans and pricing as listed
6 listed- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
Refund terms
As stated by the publisher on AWS Marketplace.
We offer a full refund of software charges for the first 48 hours billing starts if the product does not perform as described. To request a refund, email info@softwaresushi.com with your EC2 instance ID and a description of the issue. AWS infrastructure costs (EC2, EBS, data transfer) are billed by AWS and are not eligible for refund by us.
Sources
Publisher resources
1 linkLinked repositories
1 repoUnknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

