Skip to main content
Return to Blog de Seguridad de TrendAI™
AI & emerging technologiesCloud & supply chain

The Architecture Behind $1B: How Customers Run TrendAI Vision One™ on AWS, and Secure Their AI Workloads

AIEmerging technologiesCloudFinancial servicesHealthcare & life sciencesIndustrial & energyTechnology, media, & communicationsGeneral markets

TrendAI™ has surpassed $1 billion in AWS Marketplace sales, one of a select group of AWS independent software vendors (ISVs) ever to cross that line. Behind that number are more than 2,900 private offers, and thousands of security teams who closed real gaps faster because buying never slowed them down: The TrendAI Vision One™ platform deploys against existing AWS committed spend through Enterprise Discount Program (EDP) burn-down, lands on the single AWS bill finance already approves, and transacts through the channel partners they already trust.

What that unlocks is measured in security outcomes, not procurement ones: protection running in days instead of quarters, one platform watching the entire AWS footprint instead of a patchwork of tools, threats detected 70% faster, and alert queues cut from thousands to single digits. That model took a decade to build. TrendAI™ was the first security partner to adopt consumption-based billing in 2014, helped design what became AWS Private Offers, and was a design and launch partner for Channel Partner Private Offers (CPPO), the model many of AWS's top-selling partners transact through today. So the question most AWS customers ask isn't whether this model works. It's what running it well looks like. Let's look at the architecture behind it.

What customers deploy: Three common patterns

For AWS customers, every TrendAI Vision One™ deployment starts with a single CloudFormation stack, using StackSets to push resources across regions. The baseline is very light: IAM roles and policies, Lambda custom resources, SQS queues, EventBridge rules, and CloudWatch log groups, with no standing compute. As additional features are selected, deeper integrations are enabled and the permission surface grows with them, all of it visible in the template before you deploy. Across thousands of AWS Marketplace transactions, three deployment patterns come up again and again, usually in this order.

Pattern 1: Agentless cloud visibility and risk management.

Most teams don't lack findings. They lack a way to tell which ones an attacker could actually reach. This pattern starts with a single read-only connection: an IAM role onboarded once, organization-wide, via CloudFormation StackSets, with an optional CloudFormation stack that enables in-account scanning. Five capabilities inside TrendAI Vision One™ run on top of that one connection.

Four of them make up TrendAI Vision One™ Cyber Risk Exposure Management (CREM), which runs one continuous exposure loop: discovering assets across more than 80+ AWS services, assessing them against more than 600+ AWS security rules, mapping attack paths, and surfacing the exposures that are actually exploitable. Cloud Security Posture Management (CSPM) fetches asset metadata through AWS APIs and checks it against posture rules. Data Security Posture Management (DSPM) uses a temporary scanner to check S3 buckets and EBS volumes for sensitive data. Cloud Infrastructure Entitlement Management (CIEM) adds CloudTrail audit-log usage on top of CSPM to flag unused and over-privileged identities. And Agentless Vulnerability & Threat Detection uses Lambda to trigger snapshots of EBS volumes, which are scanned with a temporary EC2 instance that's torn down upon completion. For licensed Marketplace images, the EBS Direct API is used to scan without an EC2 instance. ECR images and Lambda functions are scanned by Lambda. Nothing persists, and there's no impact to running applications.

The fifth capability, Real-Time Posture Monitoring, closes the gap between scan cycles. It reacts to EventBridge configuration-change events, so posture reflects what changed minutes ago rather than what the last scheduled scan saw. (It requires Cloud Detections for AWS CloudTrail to be enabled.)

All five feed one place: unified asset inventory, prioritized risks, and XDR detections in one console, with findings mapped to the AWS Well-Architected Framework and dozens of compliance standards. The outcome: teams fix the handful of exploitable vulnerabilities, instead of working through hundreds of theoretical ones.

Figure 1. Agentless Cloud Visibility and Risk Management
Figure 1. Agentless Cloud Visibility and Risk Management

Pattern 2: Workload and container protection.

Knowing where you're exposed doesn't stop an attack already underway. This pattern contains it, and coverage scales with the estate rather than a license count fixed at purchase. For runtime defense, customers deploy TrendAI Vision One™ Server & and Workload Protection (SWP) agents on EC2, metered pay-as-you-go through Marketplace so consumption flows straight to the AWS bill. TrendAI Vision One™ Container Security covers EKS and ECS with runtime protection, deployed as pods via Helm chart on EKS or CloudFormation resources in ECS, with Fargate supported. Images are checked during development and deployment to identify common vulnerabilities and exposures (CVEs), malware, and secrets. TrendAI Vision One™ File Security adds serverless malware scanning for S3 objects, with NFS/SMB storage covered via a scanner gateway.

Figure 2. Workload and Container Protection with TrendAI Vision One™
Figure 2. Workload and Container Protection with TrendAI Vision One™

Pattern 3: Security operations on AWS telemetry.

Cloud signals in isolation rarely tell you whether something is an incident. Correlation across endpoint, identity, email, and network is what tells the security operations center (SOC) which few are real. SOC teams wire TrendAI Vision One™ XDR for Cloud and TrendAI Vision One™ Agentic SIEM into CloudTrail, GuardDuty, and Amazon Security Lake to use the logs AWS already generates, and TrendAI Vision One™ correlates those with signals from hundreds of third-party sources. Platform-wide, that means 100% MITRE ATT&CK 2025 coverage with 9,000 high-fidelity detections. For the SOC, that cuts alert volume from thousands to single digits, so the team is working on incidents instead of triaging noise.

Figure 3. CloudTrail Log Monitoring using ControlTower
Figure 3. CloudTrail Log Monitoring using ControlTower
Figure 4. CloudTrail Log Monitoring for a Single Account
Figure 4. CloudTrail Log Monitoring for a Single Account

Most customers start with one pattern and expand. The reference architecture in Figure 5 shows how the three fit together, and it's worth noting the platform itself runs on AWS, with its generative AI capabilities running on Amazon Bedrock.

Figure 5. Reference architecture: TrendAI Vision One™ on AWS
Figure 5. Reference architecture: TrendAI Vision One™ on AWS

How deeply does TrendAI Vision One™ integrate with AWS?

TrendAI Vision One™ integrates with or monitors over 80+ AWS services, roughly a third of AWS's more than 240+ services. For customers, depth is the point: fewer consoles to swivel between, fewer blind spots between tools, and one risk picture that already understands your AWS estate.

TrendAI Vision One™ ingests logs from CloudTrail, VPC Flow Logs, CloudWatch, and Amazon Security Lake, along with findings from GuardDuty, Macie, Inspector, and Security Hub. That data is correlated and prioritized through Agentic SIEM and XDR alongside endpoint and identity telemetry.

Roughly 30 of those services go deeper. Native integrations include agentless vulnerability and malware detection using temporary EC2 instances and EBS snapshots, runtime protection of EKS and ECS clusters, and serverless object scanning of S3 buckets. They also include image scanning in ECR, and prompt inspection and intervention for AI applications built on Amazon Bedrock.

The coverage spans AWS’s full surface, not just security services:

  • Compute and storage: EC2, EBS, S3, Lambda
  • Containers: ECS, EKS, Fargate, ECR
  • Detection and telemetry: CloudTrail, VPC Flow Logs, CloudWatch, Security Lake
  • Security and identity: GuardDuty, Macie, Inspector, Security Hub, IAM
  • Networking: VPC endpoints, Network Firewall
  • AI: Amazon Bedrock, including Amazon Nova

Do I get one view across AWS Security Hub and everything else?

Security Hub findings flow into TrendAI Vision One™ through Amazon Security Lake, alongside CloudTrail logs, VPC Flow Logs, WAF logs, EKS audit logs, and Route 53 Resolver query logs. Native AWS signals get correlated with TrendAI™ detections in one place. For sending TrendAI™ findings into Security Hub, TrendAI™ maintains open-source integration code, templates, and documentation on GitHub. And as an AWS Built-in ISV Competency partner, core security deploys across multiple AWS accounts with AWS-validated automation rather than one-off scripting.

What happens after Amazon GuardDuty flags something?

GuardDuty stays on; TrendAI Vision One™ makes its findings actionable. GuardDuty findings make their way to Amazon Security Lake, which XDR for Cloud ingests and correlates against over 150 detection models alongside signals from workloads, identities, endpoints, and email. With TrendAI Vision One™, an isolated finding becomes a full attack story rather than a notification in a queue. From there, Cloud Response for AWS revokes a compromised IAM user's access as a built-in action, and Security Playbooks extend it further, triggering Lambda or EventBridge to do things like isolate an EC2 instance. Either way it happens in seconds instead of waiting on a ticket queue. That's dwell time taken off the board: the hours an attacker would have used to move laterally are gone.

How does it onboard through AWS Control Tower?

Customers connect their Control Tower managed Log Archive account once, and TrendAI Vision One™ gains CloudTrail-based detections across the multi-account environment, with new accounts inheriting coverage as they're provisioned. That's the difference between “deployed in an account” and “deployed across an organization,” and it's how large enterprises get to full coverage in days. Security coverage grows at the same speed as the business, so a new team spinning up an account never creates an unprotected corner.

What about EKS, ECS, and serverless?

Container Security covers the lifecycle in order. TrendAI Vision One™ Code Security runs the TrendAI™ Artifact Scanner in your continuous integration and continuous delivery (CI/CD) pipeline, catching issues before anything deploys. Agentless Vulnerability & Threat Detection scans images already sitting in ECR. Admission control then decides whether a workload is allowed to start, and runtime protection watches it once it's running. This is, deployed as a Helm-managed pod set on EKS or CloudFormation-deployed resources on ECS, including Fargate tasks. Lambda-based File Security scans objects as they land in S3.

Does it replace AWS native security services?

No. It's designed to be better together. AWS provides foundational controls under the shared responsibility model. GuardDuty keeps detecting anomalies in your AWS control plane and network activity, and Security Hub stays your findings aggregator. TrendAI Vision One™ adds the cross-layer correlation, exposure prioritization, virtual patching, and automated response that turn those controls into outcomes, backed by 450 threat researchers and the TrendAI™ Zero Day Initiative™ (ZDI). For a 1,000-endpoint environment, that means 70% faster detection and roughly $288K a year in savings. Northeast Georgia Health System, running in AWS, cut time spent investigating false positives by 60%.

The next frontier: securing the AI era on AWS

The same customers who moved workloads to AWS over the past decade are now moving AI there, and adopting it faster than they can secure it. According to IDC research, 88% of enterprise AI proofs-of-concept never make it to production; for every 33 pilots launched, only about four graduate. IDC points to organizational readiness as the culprit, and for security teams that readiness gap has a specific shape: nobody can prove the project is safe to launch. What data is feeding the model? Do the guardrails hold up? What happens when an agent is compromised?

TrendAI Vision One™ changes that math. Because the AI stack is covered by the same platform already securing your cloud, the evidence a security review needs exists before the review starts. Approval becomes a checkpoint instead of a roadblock, and AI projects can now confidently go into production. AI is changing the ground underneath them too. When AI can discover and weaponize vulnerabilities in hours rather than months, the gap between discoverable and actively exploited shrinks to near zero. Virtual patching helps solve this issue. TrendAI Vision One™ Server and Workload Protection blocks exploit attempts on the EC2 instance itself, using intrusion prevention rules that hold even when the software is unpatched. TrendAI Vision One™ Cloud IPS does the same job further out, inspecting traffic through AWS Network Firewall so an attempt is stopped at the VPC edge before it reaches the workload. Patching still happens on your schedule with Systems Manager Patch Manager, and the rules cover the window until it comes around. The TrendAI™ ZDI often finds these vulnerabilities before the vendor does, which is how protection reaches customers an average of 96 days ahead of the vendor patch. Those rules are written against the underlying exploitation method or vulnerability class rather than individual CVEs. That means one rule covers the variants that follow, which is what scales as AI drives up bug volume. The answer isn't another point tool; it's extending the pipeline you already secure: from code, to cloud, to models, to agents.

On AWS, that looks like three layers working together:

  • AI risk visibility. TrendAI Vision One™ continuously scans AWS resources, including every Amazon Bedrock deployment, for misconfigurations, unauthorized model access, missing guardrails, and exposed sensitive data: seven categories of AI risk in all. TrendAI Vision One™ AI Security Posture Management (AI-SPM) and Data Security Posture Management (DSPM) work alongside Amazon Macie to classify sensitive data across S3, so you know exactly what's feeding your models.
  • AI application protection. Pre-deployment scanning with TrendAI Vision One™ AI Scanner and real-time enforcement with TrendAI Vision One™ AI Guard augment Amazon Bedrock Guardrails, covering prompt injection, sensitive data leakage, and unsafe outputs across inputs and outputs. This closes the gaps in the shared responsibility model. Deployment is via CloudFormation alongside existing Bedrock workloads, and with the self-hosted option, sensitive AI traffic stays in your AWS account; only scan results leave.
  • Connected AI threat detection. Bedrock activity (prompt injections, PII exposure, unsafe outputs) is correlated with signals across the whole AWS environment, so a compromised agent shows up as one connected attack story, not scattered alerts.

This is also where co-innovation with AWS runs deepest, with 2026 initiatives spanning agentic AI memory (built on Bedrock and Amazon Neptune), AI detection and response, and centralized Bedrock risk visibility. And TrendAI Vision One™'s own generative AI runs on Amazon Bedrock: we secure the stack we build on.

Getting started

Everything covered here is available today in AWS Marketplace, with no separate procurement cycle required:

The milestone matters less than what made it possible: more than a decade of TrendAI™ and AWS building side by side, so security keeps pace with wherever customers go next. And “next” is already here. Prompt injection, agent hijacking, shadow AI, and data leakage are joining ransomware and credential theft on the board's risk register, and no single vendor or cloud provider can counter them alone.

That's why this partnership keeps deepening: AWS providing the foundation and native controls, TrendAI™ adding the threat intelligence, cross-layer correlation, and AI-native protection built on top of them. The result for customers is what it has always been: better security, together. And now that protection extends to every model, application, and agent you run on AWS.