
AWS AI Competency · GenAI
Powered by agentic AI and generative AI on AWS.
Dedups.ai set out to build an AI-powered cloud security operations platform on AWS that continuously monitors cloud environments, identifies security risks and misconfigurations, investigates findings, explains business impact, recommends remediation, and supports controlled automated remediation, shrinking the gap between detection and response.
The goal was to reproduce the judgement of an experienced security analyst at machine speed and scale: not just surfacing findings, but correlating them, reasoning about their impact, and preparing safe, standardized remediation, all while keeping a human firmly in control of any consequential change. In effect, the platform acts as a tireless first responder that triages and prepares, so security engineers can focus on decisions rather than data-gathering.
Cloud environments generate security findings from many services at once, and volume grows with every new workload. Security teams spend significant time turning those raw findings into safe, prioritized action, time that does not scale linearly with headcount.
Without automation, high-risk misconfigurations could stay exposed longer than acceptable while teams struggled to keep pace with cloud growth. Dedups.ai needed a system that could investigate at machine speed, standardize how findings are handled, and preserve human oversight and a complete audit trail at every step.
Batif Services Private Limited designed and delivered an event-driven, serverless-first security operations platform on AWS. Findings from AWS Security Hub, Amazon GuardDuty, Amazon Inspector and AWS Config are routed through Amazon EventBridge into investigation workflows orchestrated by AWS Step Functions and AWS Lambda. Amazon Bedrock analyzes each finding to explain root cause, assess impact and generate remediation recommendations.
Sensitive remediation passes through human approval gates before execution. Security evidence and reports are stored in Amazon S3 and a managed database, with dashboards and APIs for continuous monitoring, keeping humans in control of consequential actions. The workflow encodes an analyst's playbook: gather context, correlate, assess, recommend, and only then act with approval.
The architecture is intentionally modular. New finding sources can be added to EventBridge without changing the investigation logic, and remediation actions are defined as discrete, permissioned steps, so the platform can grow in capability while its safety guarantees stay intact.
Architecture flow
The platform pairs generative AI with agentic, tool-using workflows to investigate and act safely across the cloud environment. Generative AI supplies the reasoning and explanation; the agentic workflow supplies the controlled, permissioned action.
Model choice
Anthropic Claude 5.0 Sonnet on Amazon Bedrock was selected for its strength at correlating findings and producing clear, standardized remediation guidance. Amazon Titan Text and Meta Llama 3 were also evaluated on reasoning quality, consistency and cost. Amazon Bedrock keeps model choice flexible, allowing the platform to adopt stronger models over time without re-architecting the workflow.
| AWS service | Purpose |
|---|---|
| Amazon Bedrock | Foundation model layer for security explanation, impact assessment and remediation recommendations. |
| AWS Security Hub | Central aggregation of security findings and posture across the environment. |
| Amazon GuardDuty | Threat detection feeding findings into the investigation pipeline. |
| Amazon Inspector | Vulnerability and workload findings for prioritization and remediation. |
| AWS Config | Configuration and compliance findings used to detect misconfigurations and drift. |
| AWS CloudTrail | Activity history used as context during investigation and for audit. |
| Amazon EventBridge | Event-driven triggering of investigation workflows from incoming findings. |
| AWS Step Functions | Orchestration of multi-step investigation and remediation workflows with approval gates. |
| AWS Lambda | Serverless execution of investigation logic and approved remediation under least privilege. |
| Amazon S3 | Secure storage of security evidence, decisions and generated reports. |
| Amazon CloudWatch | Observability across workflows, model invocation and platform health. |
| AWS IAM & AWS KMS | Least-privilege authorization for every action and customer-managed encryption keys. |
| Amazon API Gateway | Exposes monitoring and reporting APIs for the platform. |
Batif Services Private Limited acted as the end-to-end design and delivery partner, owning the engagement from architecture through to operations and handover.
A 30-minute call with the engineers who delivered this. We look at your data, your constraints and what we would build first.