NEW · What your AI agents can access vs. what they actually do with it. Live with ISMGSee how →
Agent DLP hero background

Agent DLP™ + NVIDIA OpenShell

Agent DLP,meet the sandbox.

Bedrock Data brings enterprise data context to every agent action in NVIDIA OpenShell, part of the NVIDIA Open Agent Safety Platform. Agent DLP evaluates each agent action against your data policies, and OpenShell enforces the decision before the action takes effect.

Get a Demo
Learn more
NVIDIA OpenShell sandbox
>
Bedrock Data
Agent DLP
waiting
Action
…
Data
…
Destination
…
WAITINGNo outbound action yet
Bedrock Data Policyevaluates the payload

Illustrative replay. Names and records are fictional.

Example use cases

Healthcare · PHI

Keep patient data in HIPAA-compliant environments

Agentic debugging and everyday company workflows can't move PHI outside sanctioned environments, even when the agent holds every permission the job needs.

Software · Intellectual property

Keep proprietary code inside the company

Agents can share open source code freely while your own code stays out of public issues and repositories. Bedrock Data knows which code is yours and where it may be shared.

THE PROBLEM

Least privilege doesn't meanyour data is safe.

Every permission can be correct, yet data can still leak.

  1. PROMPTT+00:00

    A debugging task comes in

    An engineer asks the agent why last night's claims_sync job failed.

    ✓ Expected work
  2. DATA ACCESST+00:41

    The agent opens the patient database

    It needs real records to find the bad row. Access is justified for debugging.

    PermissionSELECT on claims_db.patients
    ✓ Passed access review
  3. ROOT CAUSET+03:12

    It finds the root cause

    Its investigation skill says to report findings to the incident channel.

    Permissionchat:write on #eng-incidents
    ✓ Passed access review
  4. DATA LEAKT+03:15

    Patient data lands in Slack

    The report carries the patient record it found, and the whole channel can read it.

    ✕ Data leaked
SEE IT RUN

Watch Agent DLP decideinside an agent session.

Agent DLP in NVIDIA OpenShell

Illustrative replay. Names and records are fictional.

Enterprises are running fleets of long-horizon agents that fan out into thousands of sub-agents, and permissions alone can't tell them which data can safely move where. NVIDIA OpenShell enforces policy on every agent action at the sandbox boundary. Bedrock Data's supervisor middleware makes that decision data-aware, so the runtime that isolates the agent also knows what the agent is carrying.
Ali Golshan, Senior Director of Product, NVIDIA
Where Agent DLP runs

One Agent DLP,from the gateway to the sandbox.

Agent DLP already inspects agent traffic at the gateway. Inside NVIDIA OpenShell, it evaluates every action that leaves the agent’s sandbox, whether the agent uses an MCP tool, runs a command or writes its own code.

At the gateway

Tool calls between agents and MCP servers

AWS AgentCoreLiteLLM
  • Every request an agent sends to an MCP tool
  • Every response the tool sends back
  • Allow, redact or block on each call
In the sandbox

Every action that leaves an OpenShell sandbox

NVIDIAOpenShell
  • MCP tool calls
  • Command-line invocations
  • Code the agent writes itself
HOW IT WORKS

Every action gets a datadecision before it leaves the sandbox.

01
Agent in NVIDIA OpenShell

The agent issues a call

A tool call, command or message heads out of the sandbox. OpenShell authorizes it against sandbox policy first.

02
Supervisor Middleware · Bedrock Data

The middleware consults Bedrock Data

Bedrock Data plugs into OpenShell’s Supervisor Middleware. At the enforcement point, the middleware sends each request to Bedrock Data, which checks what the data is, who can access it and where it’s headed, using classification already built in place across your environment.

03
NVIDIA OpenShell

Approved or rejected

Approved calls go through. Rejected calls stop before they take effect, and the agent gets a path to revise.

WHAT BEDROCK DATA ADDS TO OPENSHELL

Ground truth on every actionan agent takes with your data.

Runtime

A decision on every authorized request

Each request gets a go or no-go based on what the data is and where it's going.

Design time

An agent's blast radius before it runs

Security teams see the data an agent can actually reach, the toxic combinations it can create and where policy would be violated.

Data-aware

Enforcement that keeps up with your data

As data and access change, the decisions OpenShell enforces change with them, and nobody rewrites a rule.

ROLLOUT

Observe a policy first.Enforce it once it's validated.

01

Connect

Add Bedrock Data to OpenShell's Supervisor Middleware. Your agents and their tools stay as they are.

02

Observe the policy

In observe-only mode, Agent DLP returns a decision on every action without enforcing it, so you see what the policy would have done.

03

Enforce once validated

When the policy behaves the way you expect, switch it to enforcement and OpenShell acts on every decision.

What teams ask before turning it on

Put your proprietary data to work with AI agents, without increasing risk.

Agent DLP brings the ground truth about your data into every NVIDIA OpenShell sandbox.

Get a Demo
Learn more