Hardened images
Pre-hardened OS and prepackaged software images, listed on AWS Marketplace. Golden baselines you can deploy in minutes, with security and compliance posture baked in. Maintained, patched, signed.
What's in the box
Production-ready out of the gate.
Each image is built with the assumption it lands in a regulated production environment on day one.
OS hardened to CIS Level 1 or Level 2
Configured to CIS benchmarks with documented exceptions. Audit-ready out of the gate. STIG variants available for federal and defense workloads.
Observability and management baked in
SSM, CloudWatch agent, vulnerability scanner, and EDR hooks pre-installed and configured to talk to your tooling.
SSO-ready, least-privilege
Pre-wired for SSO and instance-profile patterns. No long-lived credentials. Documented IAM policies that ship alongside the image.
Patched, signed, auditable
Cadence-based patching, signed images, and a published advisory log. Your auditor can trace any image back to its build.
How to deploy
Start from a hardened baseline. Customize from there.
Marketplace images are particularly useful when you're standing up a regulated workload on a tight timeline. Instead of building a hardened baseline from scratch, you start from ours and customize for your specific compliance, identity, and operating context.
For consultancies and SIs with their own Marketplace presence: we also co-list and bundle on partner terms — mention it on the form.
Discuss deploymentFeatured listing · Private AI
A hardened Private AI image, ready for regulated workloads.
The same hardening discipline applied to an open-source AI stack. Deploy it inside your VPC and run inference, embeddings, and RAG without your data ever leaving the account.
What ships in the image
- Open-source LLM runtime (vLLM / Ollama) preconfigured for GPU instances, with Llama, Mistral, and Mixtral images ready to pull.
- Embeddings + vector store wired in (pgvector / OpenSearch) so RAG workloads boot without an integration sprint.
- Network posture defaults to no-egress: traffic stays inside your VPC, no third-party API calls, no model telemetry leaving the account.
- SSO-fronted inference endpoints with per-tenant rate limits and audit logging for every prompt and completion.
- GPU drivers, CUDA, and observability hooks pre-baked — patched on the same cadence as the rest of the catalog.
Marketplace FAQ
Common questions about the hardened images.
Where are the images published?
What does CIS-aligned actually mean for these images?
Can we customize the images, or do we need to use them as-is?
How does the Private AI image differ from a self-hosted LLM setup?
Are images patched on a schedule?
Want a hardened baseline for an upcoming engagement?
Tell us the workload, the compliance bar, and the timeline. We'll point you at the right starting image.