The Containment Era is here. →Explore

Wave 1 Live · May 27, 2026 · Weekly releases

Govern the blast radius.
Before the breach.

Lab-tested, partner-validated containment deployments for AI workloads. Each architecture ships with an insertion pattern, AI-aware SmartGroup model, and baseline policy pack. Security teams deploy from day one, with no application-team compliance required.

Wave Status6 Live

Lab-validated architectures available

Release CadenceWeekly cadence

New architecture every Wednesday

Deployment Model1 managed network

Per VCA deployment, billed as Workloads

Subscribe Through
aws
Azure
Google Cloud — coming soon
6

Live now

Weekly

Release cadence

< 4 hrs

Avg. deployment

The Problem These Solve

Without containment architecture, every AI workload is an ungoverned blast radius.

Without Containment

Ungoverned
AI AgentWorkloadAttacker C2any external IPInternal ServicesunrestrictedData ExfiltrationHTTPS POSTBlast radius = entire environment

With Containment Architecture

Enforced
Governed BoundaryAI AgentWorkloadAttacker C2DENIEDPermitted ServicesALLOWEDData ExfiltrationDENIEDBlast radius = one governed workload
Two Ways to Deploy

Pick the path that matches where you are.

Every Validated Containment Architecture deploys on Aviatrix Enterprise — including the Controller, CoPilot, and Distributed Cloud Firewall. Start with a free trial or deploy directly from GitHub if you already run Enterprise today.

New to Aviatrix

Enterprise is free — every VCA included on day one

Subscribe to Aviatrix Enterprise on AWS or Azure Marketplace, finish provisioning in under 15 minutes, and deploy any live architecture within the trial window.

30-day free trial · No contract · Full platform included

Already on Enterprise

Deploy any live VCA from GitHub

Click into any live architecture below to find the blueprint for your environment — Terraform, Helm, or policy YAML. Each detail page has the full deployment guide.

Blueprint available on every live VCA · No additional license required

Release Schedule

Validated Containment Architectures

Live now
Three architectures shipped May 27, 2026 · Lab-validated · Terraform-deployable
Week 1 · May 27, 2026
Live

Contain AWS Bedrock AgentCore

Zero-trust egress for Bedrock AgentCore agents at the network layer. AI-aware SmartGroups map Bedrock workloads dynamically; default-deny MCP egress means each agent declares its allowed destinations as policy-as-code.

AWSBedrock AgentCore
Deploy this architecture
Week 1 · May 27, 2026
Live

Contain Azure AI Foundry Agents

Containment for Azure AI Foundry deployments. AI-aware SmartGroups target ai_agent resource types directly; east-west segmentation prevents agent-to-agent lateral movement and every flow is logged for compliance.

MicrosoftAzure AI Foundry
Deploy this architecture
Week 1 · May 27, 2026
Live

Contain Enterprise MCP (Obot)

Policy-as-code containment for Obot-based MCP infrastructure. FirewallPolicy CRDs let each MCP server declare its network scope; a compromised server cannot exfiltrate through ungoverned paths.

ObotMicrosoft
Deploy this architecture
Week 2 · Jun 3, 2026
Live

Contain Enterprise GitHub Pipelines

URL-path scoping for CI/CD and coding-agent workloads. Differentiate github.com/acme-corp/* from github.com/*. Blocks runtime package installs from npm, PyPI, and Docker Hub.

GitHubActions
Deploy this architecture
Week 3 · Jun 10, 2026
Live

Contain Enterprise AI Chat

Production containment for enterprise AI chat. Managed WebGroups govern which LLM providers are reachable; AI workload URL categories block file-sharing and unauthorized providers by default.

LibreChat
Deploy this architecture
Week 3 · Jun 10, 2026
Live
Plugin

Containment Plugin for Microsoft Agent Control Specification

Compile your .guardrails.yaml into Aviatrix DCF rules via the open-source acs-to-dcf shim. No Terraform blueprint — policy plugin, not a deployable architecture.

Microsoft ACSNo blueprint · Whitepaper only
Learn More
Coming soon
Four more architectures shipping weekly through June 24, 2026
Week 4 · Jun 17, 2026
Week 4

Contain Google Vertex AI Agents

Network containment for Vertex AI agent deployments on GCP. AI-aware SmartGroups keyed to Vertex AI agent identities via Cloud Asset Inventory. Completes the hyperscaler containment set.

GoogleVertex AI
Week 5 · Jun 24, 2026
Week 5

Contain Enterprise NemoClaw

Network containment for NemoClaw-powered agentic environments. AI-aware SmartGroups segment by team, environment, or tag. Instance metadata endpoint is blocked by default.

NVIDIANemoClaw
Trusted by Enterprise Security Teams
SOC 2 Type IIIndependently audited
ISO 27001Certified
500+ enterprisesIncluding 10% of the Fortune 500
Zero data-plane accessAviatrix never touches your traffic
View Aviatrix Trust Center
Get started

Start the trial.
Deploy your first VCA this afternoon.

Subscribe to Aviatrix Enterprise on AWS or Azure Marketplace, finish provisioning in under 15 minutes, then deploy any Wave 1 architecture from GitHub.

Controller 8.1+ · 1 managed network per deployment · No developer compliance required