AWS Machine Learning Blog
6/29/2026

Multi-tenant LLM analytics with row-level security: How we built a secure agent on AWS
Short summary
AWS and PAR demonstrate a three-layer architecture for secure multi-tenant LLM analytics using cryptographic signing (SigV4), semantic validation (Bedrock), and programmatic data isolation (Split-Plane SQL). Each layer operates independently to prevent cross-tenant data exposure even if the LLM is compromised. Production-ready pattern for enterprises handling sensitive data.
- •Three-layer security model: request signing + semantic validation + programmatic isolation
- •Protects against cross-tenant data leakage and LLM manipulation in production
- •Applicable to any multi-tenant LLM analytics or agent system on AWS
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



