Skip to content
Gremlin

How teams standardize and automate reliability across their organization-one service at a time.

Streamline your service offerings with our Services Detail Template, designed to showcase your offerings in detail. Easily customize layouts, add images, and provide comprehensive information about each service without the need for coding

AI Sandbox

A production-ready AI environment, deployed on AWS Local Zone or cloud, where your teams can build, test, and validate AI use cases without rebuilding the infrastructure from scratch.

What Is the AI Sandbox?

The AI Sandbox is a platform developed by Cognipeer and operated by Hepapi in partnership with AWS. It provides enterprises with a dedicated, isolated AI environment available in the AWS Local Zone or on AWS Cloud, built around the Cognipeer Console platform.

Rather than waiting for AI infrastructure to be provisioned, configured, and secured from scratch, organizations get a ready-to-operate control plane covering the full AI stack: from model inference and vector stores to agent tracing, guardrails, and RAG pipelines.

This is not a demo environment. It is designed to run real workloads, serve multiple teams simultaneously with full tenant isolation, and scale when your needs grow, including GPU-backed inference when AWS Local Zone GPU capacity becomes available.

Why It Matters for Your Organization

AI adoption in the enterprise often stalls not because of a lack of interest, but because of infrastructure friction: Who manages the models? How do you isolate data per team? How do you ensure compliance? How do you evaluate model outputs before they reach production?

The AI Sandbox eliminates that friction. It gives you:

  • A single control plane for inference, retrieval, agent execution, and monitoring
  • Tenant-level data and credential isolation across business units or projects
  • OpenAI-compatible APIs so your development teams can start without rewriting code
  • Built-in guardrails and PII protection from day one
  • Deployment on AWS Local Zone, keeping your data within your region's borders
  • GPU-ready architecture to take advantage of future Local Zone GPU capacity

"A true HubSpot drag-and-drop web page builder! Generator is SO easy to customize without having to touch any code. Highly recommend installing this."

A photo of Shaun Benson, Marketing Manager, Agriflora
Meghan Furtado - IT Services

Platform Capabilities

The AI Sandbox is built on Cognipeer Console, a production-grade multi-tenant AI control plane. Key capabilities include:

Model Inference & Model Hub

Run LLM inference across multiple providers through a single OpenAI-compatible gateway. Register, configure, and switch models without changing your application code.

Multi-Tenant Architecture

Full data, credentials, and project isolation between teams or customers, enforced at the request level, not as an afterthought.

Vector Stores & RAG Pipelines & Memory

Ingest documents, build retrieval pipelines, and serve grounded responses. Manage prompt templates with versioning and persistent memory stores - all without assembling separate infrastructure for each component.

Agent Tracing & Evaluation

Track every agent session end-to-end. Evaluate model outputs systematically before they reach production users.

Guardrails & PII Protection

Apply input/output validation policies with keywords, regex, and LLM-based guardrails. Detect and automatically redact personally identifiable information.

GPU Fleet Management

Onboard GPU hosts, deploy models, configure pools, and load balance. Ready to scale when AWS Local Zone GPU infrastructure becomes available.

Built for AWS Local Zone and Beyond

Hepapi is an AWS Advanced Tier Services Partner. The AI Sandbox is designed to run natively on AWS, including AWS Local Zones, enabling low-latency, data-residency-compliant deployments for organizations operating across any supported region

For organizations in any Local Zone or AWS region where managed AI services such as Bedrock or AgentCore are not yet available, the AI Sandbox provides an equivalent operational surface that can be deployed locally or via AWS Cloud.

This positions Hepapi as the partner that can deliver differentiated AI infrastructure today, with a clear path to scale as AWS Local Zone capabilities expand, including GPU availability.


hepapi-aws-local-zone (1)

Who Is It For?

Technical Decision-Makers

CTOs, Technical Leads, and Platform Engineers who need a production-grade AI infrastructure without the overhead of building one from scratch.

Business & Innovation Leaders

Directors and enterprise stakeholders looking to move AI initiatives forward with a defined scope, validated environment, and a trusted delivery partner.

How It Works

scoping_environment_design

Scoping & Environment Design

We align on your use cases, tenant structure, data residency requirements, and deployment target (Local Zone or AWS Cloud).

deployment_configuration

Deployment & Configuration

Hepapi deploys and configures the Cognipeer Console environment on your designated AWS infrastructure. Providers, models, vector backends, and storage are configured to meet your requirements.

onboarding_enablement

Onboarding & Enablement

Your teams are onboarded to the platform. APIs are documented, access controls are configured per tenant, and guardrails are set before workloads go live.

operate_scale

Operate & Scale

You run your AI workloads on a stable, monitored platform. Hepapi provides ongoing support, and the environment scales as your usage and GPU availability grow.

Cognipeer Agent Sandbox overview dashboard showing sandboxes, templates, volumes and runtime status
Cognipeer Console vs. AWS AI & Agent Stack
Area AWS Service Cognipeer Assessment
Inference / models Amazon Bedrock – managed inference (Claude, Nova, Llama, Mistral) 7+ providers, including Bedrock, behind a single OpenAI-compatible API AWS provides
CP abstracts
RAG Bedrock Knowledge Bases – managed ingest, embedding, reranking, source attribution Full RAG module: chunking, vector search, reranking, metadata filters On par
Vector store OpenSearch Serverless / S3 Vectors / Aurora pgvector Selectable backend: SQLite (default), Milvus, S3 Vectors On par
Managed agent Bedrock Agents – action groups, KB association, orchestration Agent service with state management, context summarization, and tool-call limits On par
Content safety Bedrock Guardrails – PII, denied topics, content filters Guardrail module: PII detection, moderation, prompt shield, custom LLM evaluator On par
OCR / documents Amazon Textract / Bedrock Data Automation OCR API (Textract or VLM based) with bounding box and confidence output On par
CP uses Textract
Speech Amazon Polly (TTS) + Transcribe (STT), separate services Single OpenAI-compatible API for speech, transcription, and translation On par
CP unified
Identity (human) Amazon Cognito / IAM Identity Center JWT, API tokens, LDAP/SAML/OIDC support, per-tenant database isolation On par
Code execution AWS Lambda / Fargate / Firecracker microVM isolated-vm (V8) + Docker-in-Docker with persistent volumes AWS stronger
GPU / model hosting Amazon SageMaker / Bedrock Custom Model Import EE GPU Fleet – distributed GPU inference On par
Observability CloudWatch + X-Ray – logs, metrics, traces Session-level tracing, health checks, alert engine AWS more mature
Orchestration AWS Step Functions – state-machine workflows Queue-based (BullMQ/Redis) with cluster task assignment AWS more mature
Batch Bedrock Batch Inference Batch service – bulk async job submission and tracking On par
Prompt management Bedrock Prompt Management + Flows Versioned templates, environment-based deployment, Prompt Optimizer (EE) Cognipeer stronger
Enterprise assistant Amazon Q Business – packaged RAG assistant Equivalent can be assembled from agent + RAG + tools; white-label ready Different
On par
AWS stronger
Cognipeer stronger / unique
Different packaging

This document is intended for internal technical evaluation. · Cognipeer Console vs. AWS AI & Agent Stack – Section 4 (simplified)

 
Cognipeer Console
Self-hosted, integrated AI application platform
AWS AgentCore + Bedrock
Managed serverless agent infrastructure

1. Positioning at a Glance

The two products look like competitors but sit at different layers. AWS offers a horizontal infrastructure (PaaS) layer: you write the agent, AWS runs and scales it securely. Cognipeer is a vertical, integrated application platform: it bundles the entire application layer – agent framework, RAG, guardrails, red-teaming, spend tracking, and voice – into a single product.

Dimension Cognipeer vs. AWS
Positioning
Cognipeer
End-to-end, multi-tenant AI application platform
AWS
Modular set of managed agent infrastructure services
Deployment
Cognipeer
Self-hosted / on-prem (K8s, Docker) + managed option
AWS
AWS account only, fully managed serverless
Model independence
Cognipeer
Provider-agnostic: OpenAI, Anthropic, Bedrock, Vertex, Azure, Together, Ollama
AWS
Model-agnostic but Bedrock-centric
Billing
Cognipeer
Infrastructure cost + license; predictable
AWS
Consumption-based (vCPU-hour + GB-hour); free while CPU waits on I/O
Lock-in
Cognipeer
Low – portable, open provider layer
AWS
High – tied to VPC, IAM, CloudWatch, Cedar, S3

In one sentence: Cognipeer's scope goes beyond AgentCore's nine services (RAG, an OpenAI-compatible API suite, prompt management, red-teaming, voice, a GPU fleet). In return, AWS goes deeper on isolation (microVM), serverless scale, and standard integrations (OTEL, Cedar policy). In many cases, the two can be complementary: AWS provides the infrastructure and security primitives, Cognipeer the application and product layer.

2. Scorecard

Area AWS vs. Cognipeer
Runtime isolation & scale
AWS
AWS
microVM, serverless
Cognipeer
isolate + Docker + volume
Sandbox / code execution (state)
Cognipeer
AWS
Code Interpreter snapshot
Cognipeer
fork / persist
Memory
On par
AWS
automatic consolidation
Cognipeer
selectable backend
Tool gateway / MCP
AWS
AWS
semantic search, one-click connectors
Cognipeer
OpenAPI/MCP + resilience
Identity
Different
AWS
workload vault, Cedar
Cognipeer
per-tenant DB, RBAC, LDAP
Browser automation
On par
AWS
CAPTCHA, replay
Cognipeer
LLM extraction, MCP
Observability / tracing
AWS
AWS
OTEL, third-party APM
Cognipeer
internal + spend + alerts
Evaluation + red-teaming
Cognipeer
AWS
13 evaluators, live scorer
Cognipeer
OWASP red-teaming
Policy / Guardrails
Split
AWS
Cedar declarative authorization
Cognipeer
PII / moderation / shield
RAG
On par
AWS
Knowledge Bases
Cognipeer
full module + rerank
Ready-made client APIs
Cognipeer
AWS
Bedrock API (proprietary)
Cognipeer
OpenAI-compatible suite
Prompt management / optimizer
Cognipeer
AWS
Prompt Management
Cognipeer
versioned + optimizer
Speech + real-time / voice
Cognipeer
AWS
Polly / Transcribe / Nova Sonic
Cognipeer
Enterprise real-time, unified
Inference / models
AWS provides
AWS
Bedrock (broad catalog)
Cognipeer
provider-agnostic (incl. Bedrock)
Deployment flexibility
Cognipeer
AWS
AWS only
Cognipeer
self-host / on-prem
On par
AWS stronger
Cognipeer stronger / unique
Different / Split

3. When to Choose Which

Choose AWS if…
● You are already in the AWS ecosystem; IAM, VPC, and CloudWatch are your standard
● You need the tightest session isolation (microVM) and effectively unlimited serverless scale
● You want to write the agent with your own framework (LangGraph, CrewAI) and only operate it
● Minimizing operational burden is your priority
Choose Cognipeer if…
● Self-hosted, on-prem, or air-gapped deployment and data sovereignty are a must
● You want agent, RAG, evaluation, guardrails, and voice in a single product
● Fast go-live with an OpenAI-compatible drop-in API is your priority
● You want multiple providers (no vendor lock-in) and predictable cost
Sources
  • Amazon Bedrock AgentCore documentation
  • AgentCore GA announcement (October 2025)
  • Amazon Bedrock documentation (Knowledge Bases, Guardrails, Agents)
  • AgentCore pricing page
  • Cognipeer Console codebase review (Community + Enterprise editions)

This document is prepared for technical evaluation purposes.

 

Cognipeer Console
Self-hosted, integrated AI application platform
AWS AgentCore + Bedrock
Managed serverless agent infrastructure

1. Positioning at a Glance

The two products look like competitors but sit at different layers. AWS offers a horizontal infrastructure (PaaS) layer: you write the agent, AWS runs and scales it securely. Cognipeer is a vertical, integrated application platform: it bundles the entire application layer – agent framework, RAG, guardrails, red-teaming, spend tracking, and voice – into a single product.

Dimension AWS (AgentCore + Bedrock family)
Positioning
Cognipeer
End-to-end, multi-tenant AI application platform
AWS
Modular set of managed agent infrastructure services
Deployment
Cognipeer
Self-hosted / on-prem (K8s, Docker) + managed option
AWS
AWS account only, fully managed serverless
Model independence
Cognipeer
Provider-agnostic: OpenAI, Anthropic, Bedrock, Vertex, Azure, Together, Ollama
AWS
Model-agnostic but Bedrock-centric
Billing
Cognipeer
Infrastructure cost + license; predictable
AWS
Consumption-based (vCPU-hour + GB-hour); free while CPU waits on I/O
Lock-in
Cognipeer
Low – portable, open provider layer
AWS
High – tied to VPC, IAM, CloudWatch, Cedar, S3

In one sentence: Cognipeer's scope goes beyond AgentCore's nine services (RAG, an OpenAI-compatible API suite, prompt management, red-teaming, voice, a GPU fleet). In return, AWS goes deeper on isolation (microVM), serverless scale, and standard integrations (OTEL, Cedar policy). In many cases, the two can be complementary: AWS provides the infrastructure and security primitives, Cognipeer the application and product layer.

2. Scorecard

Area AWS Cognipeer Standout
Runtime isolation & scale microVM, serverless isolate + Docker + volume AWS
Sandbox / code execution (state) Code Interpreter snapshot / fork / persist Cognipeer
Memory automatic consolidation selectable backend On par
Tool gateway / MCP semantic search, one-click connectors OpenAPI/MCP + resilience AWS
Identity workload vault, Cedar per-tenant DB, RBAC, LDAP Different
Browser automation CAPTCHA, replay LLM extraction, MCP On par
Observability / tracing OTEL, third-party APM internal + spend + alerts AWS
Evaluation + red-teaming 13 evaluators, live scorer + OWASP red-teaming Cognipeer
Policy / Guardrails Cedar declarative authorization PII / moderation / shield Split
RAG Knowledge Bases full module + rerank On par
Ready-made client APIs Bedrock API (proprietary) OpenAI-compatible suite Cognipeer
Prompt management / optimizer Prompt Management versioned + optimizer Cognipeer
Speech + real-time / voice Polly / Transcribe / Nova Sonic Enterprise real-time, unified Cognipeer
Inference / models Bedrock (broad catalog) provider-agnostic (incl. Bedrock) AWS provides
Deployment flexibility AWS only self-host / on-prem Cognipeer
On par
AWS stronger
Cognipeer stronger / unique
Different / Split

3. When to Choose Which

Choose AWS if…
● You are already in the AWS ecosystem; IAM, VPC, and CloudWatch are your standard
● You need the tightest session isolation (microVM) and effectively unlimited serverless scale
● You want to write the agent with your own framework (LangGraph, CrewAI) and only operate it
● Minimizing operational burden is your priority
Choose Cognipeer if…
● Self-hosted, on-prem, or air-gapped deployment and data sovereignty are a must
● You want agent, RAG, evaluation, guardrails, and voice in a single product
● Fast go-live with an OpenAI-compatible drop-in API is your priority
● You want multiple providers (no vendor lock-in) and predictable cost

 

Cognipeer Console
Self-hosted, integrated AI application platform
AWS AgentCore + Bedrock
Managed serverless agent infrastructure

1. Positioning at a Glance

The two products look like competitors but sit at different layers. AWS offers a horizontal infrastructure (PaaS) layer: you write the agent, AWS runs and scales it securely. Cognipeer is a vertical, integrated application platform: it bundles the entire application layer – agent framework, RAG, guardrails, red-teaming, spend tracking, and voice – into a single product.

Dimension Cognipeer Console AWS (AgentCore + Bedrock family)
Positioning End-to-end, multi-tenant AI application platform Modular set of managed agent infrastructure services
Deployment Self-hosted / on-prem (K8s, Docker) + managed option AWS account only, fully managed serverless
Model independence Provider-agnostic: OpenAI, Anthropic, Bedrock, Vertex, Azure, Together, Ollama Model-agnostic but Bedrock-centric
Billing Infrastructure cost + license; predictable Consumption-based (vCPU-hour + GB-hour); free while CPU waits on I/O
Lock-in Low – portable, open provider layer High – tied to VPC, IAM, CloudWatch, Cedar, S3

In one sentence: Cognipeer's scope goes beyond AgentCore's nine services (RAG, an OpenAI-compatible API suite, prompt management, red-teaming, voice, a GPU fleet). In return, AWS goes deeper on isolation (microVM), serverless scale, and standard integrations (OTEL, Cedar policy). In many cases, the two can be complementary: AWS provides the infrastructure and security primitives, Cognipeer the application and product layer.

2. Scorecard

Area AWS Cognipeer Standout
Runtime isolation & scale microVM, serverless isolate + Docker + volume AWS
Sandbox / code execution (state) Code Interpreter snapshot / fork / persist Cognipeer
Memory automatic consolidation selectable backend On par
Tool gateway / MCP semantic search, one-click connectors OpenAPI/MCP + resilience AWS
Identity workload vault, Cedar per-tenant DB, RBAC, LDAP Different
Browser automation CAPTCHA, replay LLM extraction, MCP On par
Observability / tracing OTEL, third-party APM internal + spend + alerts AWS
Evaluation + red-teaming 13 evaluators, live scorer + OWASP red-teaming Cognipeer
Policy / Guardrails Cedar declarative authorization PII / moderation / shield Split
RAG Knowledge Bases full module + rerank On par
Ready-made client APIs Bedrock API (proprietary) OpenAI-compatible suite Cognipeer
Prompt management / optimizer Prompt Management versioned + optimizer Cognipeer
Speech + real-time / voice Polly / Transcribe / Nova Sonic Enterprise real-time, unified Cognipeer
Inference / models Bedrock (broad catalog) provider-agnostic (incl. Bedrock) AWS provides
Deployment flexibility AWS only self-host / on-prem Cognipeer
On par
AWS stronger
Cognipeer stronger / unique
Different / Split

3. When to Choose Which

Choose AWS if…
● You are already in the AWS ecosystem; IAM, VPC, and CloudWatch are your standard
● You need the tightest session isolation (microVM) and effectively unlimited serverless scale
● You want to write the agent with your own framework (LangGraph, CrewAI) and only operate it
● Minimizing operational burden is your priority
Choose Cognipeer if…
● Self-hosted, on-prem, or air-gapped deployment and data sovereignty are a must
● You want agent, RAG, evaluation, guardrails, and voice in a single product
● Fast go-live with an OpenAI-compatible drop-in API is your priority
● You want multiple providers (no vendor lock-in) and predictable cost
Tell The Reader More

Cognipeer Console vs. AWS AI & Agent Stack

Section 4 - Comparison with Other AWS Services (Beyond AgentCore). AWS services that map to Cognipeer capabilities outside
the AgentCore scope.

 

Area AWS vs. Cognipeer
Inference / models
AWS provides
CP abstracts
AWS
Amazon Bedrock – managed inference (Claude, Nova, Llama, Mistral)
Cognipeer
7+ providers, including Bedrock, behind a single OpenAI-compatible API
RAG
On par
AWS
Bedrock Knowledge Bases – managed ingest, embedding, reranking, source attribution
Cognipeer
Full RAG module: chunking, vector search, reranking, metadata filters
Vector store
On par
AWS
OpenSearch Serverless / S3 Vectors / Aurora pgvector
Cognipeer
Selectable backend: SQLite (default), Milvus, S3 Vectors
Managed agent
On par
AWS
Bedrock Agents – action groups, KB association, orchestration
Cognipeer
Agent service with state management, context summarization, and tool-call limits
Content safety
On par
AWS
Bedrock Guardrails – PII, denied topics, content filters
Cognipeer
Guardrail module: PII detection, moderation, prompt shield, custom LLM evaluator
OCR / documents
On par
CP uses Textract
AWS
Amazon Textract / Bedrock Data Automation
Cognipeer
OCR API (Textract or VLM based) with bounding box and confidence output
Speech
On par
CP unified
AWS
Amazon Polly (TTS) + Transcribe (STT), separate services
Cognipeer
Single OpenAI-compatible API for speech, transcription, and translation
Identity (human)
On par
AWS
Amazon Cognito / IAM Identity Center
Cognipeer
JWT, API tokens, LDAP/SAML/OIDC support, per-tenant database isolation
Code execution
AWS stronger
AWS
AWS Lambda / Fargate / Firecracker microVM
Cognipeer
isolated-vm (V8) + Docker-in-Docker with persistent volumes
GPU / model hosting
On par
AWS
Amazon SageMaker / Bedrock Custom Model Import
Cognipeer
EE GPU Fleet – distributed GPU inference
Observability
AWS more mature
AWS
CloudWatch + X-Ray – logs, metrics, traces
Cognipeer
Session-level tracing, health checks, alert engine
Orchestration
AWS more mature
AWS
AWS Step Functions – state-machine workflows
Cognipeer
Queue-based (BullMQ/Redis) with cluster task assignment
Batch
On par
AWS
Bedrock Batch Inference
Cognipeer
Batch service – bulk async job submission and tracking
Prompt management
Cognipeer stronger
AWS
Bedrock Prompt Management + Flows
Cognipeer
Versioned templates, environment-based deployment, Prompt Optimizer (EE)
Enterprise assistant
Different
AWS
Amazon Q Business – packaged RAG assistant
Cognipeer
Equivalent can be assembled from agent + RAG + tools; white-label ready
On par
AWS stronger
Cognipeer stronger / unique
Different packaging

This document is intended for internal technical evaluation. · Cognipeer Console vs. AWS AI & Agent Stack – Section 4 (simplified)

 

Ready to Run AI at Scale?

Whether you are evaluating AI infrastructure for the first time or looking to consolidate fragmented tooling into a single, governable platform, the AI Sandbox provides a production-ready starting point, deployed on AWS and operated by Hepapi.



Get in touch to discuss your AI Sandbox deployment.