BlueRock Security provides embedded runtime security into your cloud Ubuntu Linux and container images. Simply select the distribution for your instances or nodes and launch a secure by default runtime to deploy your applications on top of. BlueRock minimizes the overhead of vulnerabilty remediation by protecting against ~70% of both known and unknown vulnerability exploits saving hours of time for developers.
BlueRock Security gives organizations a secure by default compute foundation to counter AI speed attacks and save time for your developers. The solution provides Runtime Reachability Intelligence (RRIQ) to identify what libraries and code paths actually run mapped to exploitable CVEs to help prioritize the most important fixes. This helps minimize false positives from SCA and static analysis scans and help control the endless churn of the vulnerability scan and patch process.
This BlueRock Amazon Linux 2023 image offers the following benefits:
Visibility into which libraries and code paths actually run in your app environments.
Reduction in your vulnerability patch list by 70 - 90% saving time spent on false positive vulnerabilities on a continual basis.
Evidence-based reachability reports that align dev and security on what to fix first.
Runtime protection for apps containers and nodes without legacy bolt on agents.
Java and Python App runtime guardrails to detect and block against Java and Python deserialization path traversal and other package and framework vulnerabilities.
The BlueRock Compute Firewall delivers real-time attack prevention to protect app container and host runtime environments. Always-on and transparent BlueRock removes the need to deploy yet another security agent and protects workloads without requiring developer code changes.
Instead of searching for needles in noisy telemetry haystacks BlueRock proactively enforces runtime invariants - precise guardrails capable of disrupting entire classes of attacker exploit chains. This invariant-based approach flips the script on detect and respond clearly defining what should never happen in uncompromised workloads.
This approach enables BlueRock to see and stop attacker behavior and avoid false positives. It does not guess. It blocks only definitively malicious actions. And it does so with little to no performance impact.
Highlights
Embedded runtime security. Secure by default - no installation required
Save developers time by blocking ~70% of unknown and known exploits to reduce the overhead of patching
Provides security teams with in-depth visibility of exploit attempts and configuration drift.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing has one pricing dimension: BlueRock Compute Runtime Security, billed as a contract. You pay based on the number of units you commit to. This product deploys as an EC2 image on your own AWS infrastructure. It provides runtime security for agentic workflows, including observability of agent execution and guardrails applied as actions occur. Because there is a single dimension, pricing scales with the quantity of units you select. There are no separate tiers or add-on dimensions to combine on the Marketplace.
Top-of-mind questions for buyers
What counts as one unit of BlueRock Compute Runtime Security for billing?
A unit represents runtime security coverage tied to the EC2 image you deploy on your own AWS infrastructure. You commit to a number of units under the contract, and your cost scales with that quantity. The Marketplace table does not define a smaller sub-unit, so confirm exact unit mapping with the vendor.
Does deploying this on my own AWS infrastructure require changes to my agents or workflows?
No. BlueRock connects at the execution layer, so you do not instrument the agent, add logging hooks, or change how the workflow is built. Self-hosted deployment on your own AWS uses CloudFormation and takes under five minutes. Observability runs alongside execution without meaningfully affecting workflow performance.
What runtime security capabilities does this contract dimension actually cover?
It covers observability of agent execution and guardrails applied as actions occur. You trace agent decisions, tool calls, and downstream actions in one connected view. Guardrails evaluate each execution step and can allow, constrain, or block actions based on runtime signals across tools and connected systems.
bluerock.io+3
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
The following AWS services and resources are deployed with the CloudFormation template:
EC2 instance with EBS storage
IAM role with S3, logs, and IAM permissions
VPC with subnets
S3 bucket for policy storage
CloudWatch Log Group for events
Internet Gateway for instance access
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Support available Monday through Friday during business hours. Premium support available through request customer-support@bluerock.io
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
The BlueRock Agentic Sandbox and Secure MCP Server provides AI development teams with a production-ready environment to build, test, and operate MCP-based agentic workflows on AWS.
Bluerock TMS is a solution that helps businesses in the transportation industry streamline logistic operations and delivery processes with our Distribution solution having focus on detailed planning and route optimization including embedded driver app.
Bluerock TMS is a solution that helps businesses in the transportation industry streamline logistic operations and delivery processes. Our TMS solution supports manufacturing companies and logistics experts (3PL, 4PL, ...).
BlueRock Security provides embedded runtime security into your cloud Linux and container images. Simply select the distribution for your instances or nodes and launch a secure by default runtime to deploy your applications on top of. BlueRock minimizes the overhead of vulnerabilty remediation by protecting against ~70% of both known and unknown vulnerability exploits saving hours of time for developers.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.