Benchling runs multi-tenant AI agent code using Amazon Bedrock AgentCore Code Interpreter in VPC mode
Benchling described a defense-in-depth architecture to run AI agent‑generated scientific code across thousands of life‑sciences tenants using Amazon Bedrock AgentCore’s Code Interpreter in VPC mode. The setup places untrusted executions in a separate AWS account (the “Untrusted Code Account”), enforces DNS-level controls with Route 53 Resolver DNS Firewall, restricts network paths to specific VPC endpoints, injects per-job credentials via AWS STS, and runs continuous validation; the architecture reportedly handles >600 code execution sessions per day across >250 tenants per week with zero security incidents.